Legal
Draft, pending legal review
Privacy Policy
What Evelyst collects, why, who else handles it, how long we keep it, and what you can ask us to do with it.
Last updated 8 October 2026
Read only the left column for the gist. The full text on the right is the part that counts.
1 · Who we are
Evelyst is a small business in the Philippines, and its owner is the person to write to about your privacy, at privacy@evelyst.com.
1.1 This Privacy Policy explains how Evelyst Software Publishing, a sole proprietorship registered with the Department of Trade and Industry (Business Name No. 8503538) ("Evelyst", "we", "us"), collects, uses, shares, keeps and deletes Personal Data.
1.2 Our general email address is hello@evelyst.com.
1.3 Data Protection Officer. Evelyst has designated its owner as its Data Protection Officer. You can reach the Data Protection Officer at privacy@evelyst.com.
1.4 In this Policy:
- (a) "Sites" means evelyst.com and its pages.
- (b) "Service" means the Evelyst software: the Analyst, an AI analytics application at app.evelyst.com, and Evelyst POS at pos.evelyst.com, with the emails and support that come with them.
- (c) "Customer" means the business that holds an Evelyst account, and "you" means the person reading this Policy: a visitor, someone on the waitlist, a Customer or its owner, or a person whose data a Customer puts into the Service.
- (d) "Customer Data" means data that a Customer or its users put into the Service, and data the Service creates from it, including business records, uploads, questions and answers, notes and Evelyst POS records. "Customer Personal Data" means the Personal Data within Customer Data.
- (e) "Personal Data" means information from which an individual is identified, or can reasonably be identified.
1.5 This Policy is written to meet the Data Privacy Act of 2012 (Republic Act No. 10173) of the Philippines and its Implementing Rules and Regulations, and the other laws named in it where they apply. It works alongside our Terms of Service (/terms) and, for Customer Data, our Data Processing Addendum (___ (missing: the Data Processing Addendum page is not published in this build)) and our list of sub-processors (___ (missing: the sub-processors page is not published in this build)).
1.6 Each section starts with a plain sentence to help you read it. Where a plain sentence and the full text differ, the full text applies.
2 · Our two roles
For your own account, messages and waitlist entry we decide how your data is used; for the records your business puts in, including its staff and customers, your business decides and we handle them for it.
2.1 Where we are the controller. Evelyst is the personal information controller for:
- (a) data about visitors to the Sites;
- (b) waitlist entries and the optional answers given on the waitlist thank-you page;
- (c) messages sent through the contact form or to our email addresses;
- (d) the account data of a Customer's owner (sign-in details and the session described in section 12), and the sign-in security records for every sign-in to the Service, including staff sign-ins to Evelyst POS (clause 3.4(e));
- (e) billing contact details and subscription status;
- (f) support messages; and
- (g) preferences about the emails we send.
2.2 Where we are the processor. For Customer Data, the Customer is the personal information controller and Evelyst is its personal information processor. This includes:
- (a) sales and expense records, spreadsheet files, pasted text, and photos of receipts and notebook pages;
- (b) questions asked of the Analyst, its answers, and notes;
- (c) Evelyst POS data, including staff accounts, orders and any details a restaurant enters about its own customers; and
- (d) any uploads that contain the names or other Personal Data of staff, customers, suppliers or anyone else.
2.3 For Customer Personal Data, we process it only on the Customer's documented instructions, as set out in the ___ (missing: the Data Processing Addendum page is not published in this build). The Customer is responsible for having a lawful basis for the Personal Data it puts into the Service, and for giving its own staff and customers any notice the law requires.
2.4 If you are a staff member or customer of a business that uses Evelyst, please send requests about your data to that business. If we receive such a request, we will pass it to the business where we can identify it, tell you that we have done so, and help the business answer it as the ___ (missing: the Data Processing Addendum page is not published in this build) requires.
2.5 Sections 3 to 9 describe how we handle Customer Data too, so that Customers and their people can see what happens to it. Where the ___ (missing: the Data Processing Addendum page is not published in this build) and this Policy differ about Customer Data, the ___ (missing: the Data Processing Addendum page is not published in this build) applies.
3 · What we collect, by surface
We keep what you or your business give us, from your email address to your records, questions and till sales, plus the technical data needed to sign you in and keep the service safe.
3.1 The Sites. Cloudflare hosts the Sites. When you visit, Cloudflare processes the technical data your browser sends, such as your IP address, browser type, the page requested and the page you came from, to deliver and protect the Sites. We use Cloudflare Web Analytics to count visits in aggregate; it sets no cookies. The Sites use self-hosted fonts and load no third-party scripts other than Cloudflare Web Analytics and Cloudflare Turnstile (clause 3.3). If you switch between the light and dark themes, the Sites save your choice under the key theme in your browser's local storage; it stays on your device and is not sent to us. For the length of a visit, the Sites also keep two things in your browser's session storage, which your browser clears when the tab is closed: the tag in a link we shared, if you arrived through one (the r and n values in the address), which is sent with any form you submit so that we know which link brought you; and, after you join the waitlist, the email address you gave, so that the thank-you page can show it and put it back in the form if you want to correct it.
3.2 The waitlist. To join the waitlist, you give us your email address. On the thank-you page you may also answer, all optionally:
- (a) what kind of business it is;
- (b) where it is, and, if you choose "Somewhere else", the country you type;
- (c) how you keep your records now (you may pick more than one);
- (d) how many people work there, you included; and
- (e) any remarks.
We also record when you joined, when you last changed your answers, and the link tag described in clause 3.1, if there was one. We keep one entry per email address; joining again or answering again updates it.
3.3 The contact form and our email addresses. Through the contact form we collect the topic, your name (optional), your email address and your message. If you choose "Feedback or review", we also record whether you ticked "You may quote me, with my business name." Cloudflare Turnstile runs on the contact form and the waitlist form; Cloudflare receives technical data from your browser, such as your IP address, to tell people from automated abuse. Both forms are received by a server function run by Supabase (clause 6.1(a)) and stored in our database. To limit abuse, that function keeps a salted one-way hash of your IP address, not the address itself: with each entry, for as long as the entry is kept (clauses 8.1(j) and 8.1(k)), and in a count of recent submissions that it clears after a day. When you send the contact form, we are told by an email sent through Resend, and that notification, with your message, reaches our inbox at Google (clause 6.1(f)). If you email hello@evelyst.com, support@evelyst.com or privacy@evelyst.com, we receive your address, your name as your email shows it, your message and any attachments. If you choose to message us through a third-party channel such as Messenger, that platform also processes your message under its own privacy terms.
3.4 Your account. For a Customer's owner, and for sign-ins to the Service, we collect:
- (a) your email address, which you use to sign in, and your name if you give it;
- (b) your business name and settings, such as currency, time zone and store or branch names;
- (c) your password, which is handled by our authentication provider, Supabase, and stored by it in hashed form; we do not store it ourselves;
- (d) the
ev_sessioncookie, which keeps you signed in to the Analyst for up to 30 days (section 12); - (e) sign-in security records: for each attempt to sign in to the Service, by the owner or by staff, or to look up a store, the email address (for an owner) or store code and username (for staff) that was tried, the IP address it came from, whether it succeeded, and when;
- (f) your subscription status: plan, status, trial end date, current period and any cancellation; and
- (g) usage records for each AI request: which task it was, the model, the number of tokens and the cost. These records contain no text of your questions or answers.
3.5 Billing through Paddle. When paid plans open, Paddle.com acts as our reseller and Merchant of Record. Paddle collects your payment details, billing name and address and tax information directly, under its own privacy notice (clause 6.1(g)). We receive from Paddle your name, email address, country, plan, subscription status and transaction references. ___ (missing: confirm the fields Paddle's webhook sends) Evelyst doesn't receive or store your payment card number.
3.6 Uploads and imports. You can bring records into the Analyst as spreadsheet files (.csv, .xlsx), pasted text or tables, photos of receipts and notebook pages, and entries typed as a sentence or into a form.
- (a) We keep the rows you confirm, the column matching for a file, and, for a receipt, the amount, date, payee, category and receipt number.
- (b) We do not keep the original file or photo after it has been read. It exists on our server only while it is processed and, where the AI reads it, in the request sent to our AI provider (section 5).
- (c) Any Personal Data in an upload, such as a customer's or supplier's name, a phone number, handwriting or card digits on a receipt, is processed as Customer Personal Data.
- (d) We also keep notes you ask the Analyst to remember (in your original words), targets, watches, product name aliases and suggested moves.
3.7 Questions and answers. We store your questions to the Analyst and its answers in full, as typed, including any names in them. We also keep each conversation's title, a record of how each answer was produced (which calculations ran, the result of our checks, timing and cost) and any feedback you give on an answer. Replacing staff names (section 5) applies only to what is sent to our AI provider, not to what we store. When you delete a conversation, it is hidden from you at once and removed as section 8 describes.
3.8 The Monday review and watch emails. If they are switched on for your account, we send the Monday review and watch alerts to the owner's email address from review@evelyst.com. They contain your business name, figures for the week, a few lines worked out from your records, a suggested move and links back to the Analyst. We keep your email settings (on or off, which day, and an unsubscribe token). Account emails, such as password emails, are sent through Supabase's authentication service. ___ (missing: confirm Supabase Auth email sender (built-in or custom SMTP))
3.9 Support. When you ask for help, we keep your messages, our replies, and the account details we look up to help you.
3.10 Evelyst POS. For a restaurant using Evelyst POS, we process on its behalf:
- (a) Staff accounts: each staff member's full name, username, role, branches and whether the account is active. The till generates the sign-in address itself; staff are not asked for an email address or phone number. Passwords are stored by Supabase in hashed form.
- (b) Orders: items, quantities, prices, totals, discounts, order type, date and time, branch, the staff member who rang up the sale, and, for a cancelled sale, who cancelled it and why.
- (c) Payments: the payment method and an optional reference the cashier types, such as the bank terminal's transaction reference for a card payment. Evelyst POS records payments; it does not process them, and it records no payment card numbers.
- (d) Customer label: an optional short label of up to 40 characters, such as a name or a table, which prints on the receipt.
- (e) Receipts: a receipt prints the cashier's first name.
- (f) Stock changes: which staff member made each change, with an optional note.
- (g) Senior Citizen and PWD discounts: when a cashier applies a Senior Citizen or PWD discount, the till records the discount and its amount, and no customer name or label. Evelyst POS stores no Senior Citizen or PWD ID numbers: the till doesn't ask for one, and our database refuses one. The restaurant keeps its own Senior Citizen and PWD record, as the BIR's rules require of it.
- (h) On the tablet: the till keeps its sign-in session, the store's details, open carts (including any customer label and any sale still being sent), the last receipt and display preferences in the browser's local storage on that device.
- (i) Menu photos a restaurant uploads are stored so the till can show them, and anyone with a photo's link can view it. Please don't upload photos of people.
- (j) The sales feed: where a Customer uses both Evelyst POS and the Analyst, sales are copied into the Analyst each hour, and when you press Update now, as product lines: product, category, quantity, prices, cost, date and time, branch name and payment method name. Staff names, customer labels, cancellation reasons, discount details and payment references are not copied.
3.11 Where it comes from. We collect Personal Data directly from you; from the Customer, for data about its staff and customers; from Paddle, for billing status; and automatically from your browser or device, for the technical data described above.
3.12 How it is handled. We process Personal Data electronically. It is stored in our database, run by Supabase in Singapore. The Analyst's server runs on Railway in Singapore. Parts of the data are sent to the providers in section 6, for the purposes listed there. Inside Evelyst, only the owner may access Customer Data, and only to give support you ask for, to handle a request under this Policy, to keep the Service secure, or to meet a legal duty. We don't buy Personal Data, and we don't add data about you from other sources such as data brokers.
3.13 Please don't send us sensitive personal information. Apart from the discount record in clause 4.4, the Service doesn't need government ID numbers, health information or similar details. Please don't put them into questions, notes, uploads or customer labels.
4 · Why, and on what basis
We use your data to run the service, keep it safe and meet the law, and we send marketing email only to people who joined the waitlist.
4.1 We use Personal Data for the following purposes and on the following lawful bases under Section 12 of the Data Privacy Act:
- (a) Delivering and protecting the Sites (technical data, Turnstile checks): our legitimate interests in keeping the Sites available and free of automated abuse.
- (b) Counting visits (aggregate analytics with no cookies): our legitimate interests in knowing which pages are read.
- (c) The waitlist email (your email address): your consent, given by joining the waitlist (section 11).
- (d) The optional waitlist answers: your consent, given by choosing to answer. We read them ourselves, and in total across the list, to choose the examples in the monthly email and to decide which calendars, imports and features to build first. Everyone on the list gets the same email. You can skip any question.
- (e) Replying to messages and support requests: our legitimate interests in answering people who write to us and, for Customers, the performance of our contract.
- (f) Quoting your feedback with your business name: your consent, given by ticking the box. You can withdraw it at any time, and we will stop using the quote.
- (g) Providing the account and the Service (account data and Customer Data): the performance of our contract with the Customer. For Customer Personal Data, we act on the Customer's instructions, and the Customer's own lawful basis applies.
- (h) Sign-in security and preventing abuse (sign-in security records, rate limits): our legitimate interests in protecting accounts and the Service.
- (i) Billing and tax (plan, status, billing contact): the performance of our contract and our legal obligations to keep tax and accounting records.
- (j) The Monday review and watch emails: the performance of our contract, as part of the Service. You can turn them off (clause 11.5).
- (k) Service and legal notices, such as security notices and changes to this Policy: the performance of our contract and our legal obligations.
- (l) Usage and cost records (which contain no text): our legitimate interests in applying fair-use limits, controlling costs and finding faults.
- (m) Meeting legal duties and handling legal claims: our legal obligations and, for claims, our legitimate interests.
4.2 We don't use Customer Data for purposes of our own, such as marketing or training AI models. We use it to provide the Service to the Customer, to fix problems in it, and to keep it secure.
4.3 We don't carry out direct marketing other than the waitlist email in clause 4.1(c), and we don't carry out profiling.
4.4 We don't ask for sensitive personal information, with one exception that comes from Philippine law. When a cashier applies a Senior Citizen or PWD discount, Evelyst POS records that the discount was given. The record holds no customer name and no ID number. But a restaurant that links it to its own Senior Citizen and PWD record could learn from it that a customer is 60 or over or has a disability. So we treat these records as possibly sensitive personal information. We process them only as Customer Data, to record the sale. The sales feed doesn't pass which discount was given to the Analyst or our AI provider (clause 3.10(j)), and we don't use these records for any purpose of our own. If a Customer puts other sensitive personal information into the Service, we process it only as Customer Data, on the Customer's instructions under the ___ (missing: the Data Processing Addendum page is not published in this build).
4.5 If we want to use Personal Data for a purpose not described here, we will tell you before we do so and, where the law requires, ask for your consent.
5 · How the AI works with your data
What you type or upload can reach our AI provider, OpenAI, including any names in it: in text we replace the names of staff we know about with their role, but not in photos, and it can miss a name typed in an unusual way.
5.1 The Analyst uses AI models provided by OpenAI through its API to understand your questions, to write answers in words, to read figures from photos and pasted text, and to write the opening lines of the Monday review. We may change the model or the provider; any change of provider will be shown on ___ (missing: the sub-processors page is not published in this build) as the ___ (missing: the Data Processing Addendum page is not published in this build) describes.
5.2 What is sent to OpenAI.
- (a) Your questions, notes, entries typed as sentences, and pasted text that is not a table, word for word, except that the names of staff we know about (from your team list) are replaced with their role, such as "a staff member" or "a manager".
- (b) The earlier messages of the same conversation, which are sent again with each new question so the AI can follow it, and a shortened list of up to your last 20 questions.
- (c) Figures our code has worked out from your records, together with product, category and branch names, short notes about the quality of your data, and the titles of suggested moves you have open. These titles are not checked for staff names.
- (d) Photos of receipts and notebook pages, which are sent whole, as images. Nothing on a photo is hidden or replaced. Anything legible on it, such as names, phone numbers, addresses, handwriting or card digits, reaches OpenAI.
- (e) Your expense categories and today's date, when the AI reads an entry or a receipt.
5.3 The limits of name replacement. Replacing staff names applies to text only, not to photos. It can miss a first name shorter than three letters, a nickname, a surname on its own, a misspelling, or a name that is also the name of one of your products. It does not cover the names of customers, suppliers or anyone else. So any such name, phone number or other Personal Data in what you type or upload can reach OpenAI.
5.4 What is not sent to OpenAI:
- (a) the owner's name and email address, and the business name;
- (b) passwords and sign-in tokens;
- (c) spreadsheet files and pasted tables, which our own code reads without AI; and
- (d) the Evelyst POS data that the sales feed does not copy (clause 3.10(j)): staff names, customer labels, cancellation reasons, discount details and payment references, unless someone types them into the Analyst.
5.5 Training and retention at OpenAI. We don't train AI models on Customer Data. Under OpenAI's Services Agreement, OpenAI does not use content sent through its API to develop or improve its models unless the customer agrees. OpenAI may keep API data for a limited period, as its terms describe, for example to monitor for abuse. OpenAI's Data Processing Addendum is part of that agreement, and OpenAI keeps its abuse-monitoring logs for up to 30 days.
5.6 The logic involved. For a question, the Analyst works in four steps:
- (a) the AI chooses which of our calculations to run;
- (b) our code runs them on your records and works out every figure;
- (c) the AI writes the answer from those figures; and
- (d) our code checks that every number in the answer can be traced to the figures it worked out. If a number can't be traced, the answer is retried, replaced with a plain summary, or the Analyst says it can't answer.
Code computes the figures in answers. There are three exceptions:
- when you import from a photo or pasted text, the AI reads the figures, and you confirm them in a preview before they are added;
- a receipt photo fills in an expense form that you check before you save it; and
- an answer about earlier messages in a conversation is checked only against the figures already in that conversation.
AI answers can still be wrong or incomplete, and they are only as good as your records. They are information for you to judge; nothing is decided, and no record is changed, unless you choose to act.
5.7 No automated decisions about individuals. Evelyst does not use AI or other automated processing to make decisions about any individual, or to evaluate, score or profile staff, customers or anyone else. The Service is built to analyse a business's records, not to assess people. Watch alerts are triggered by fixed thresholds in our code and do not use AI.
6 · Who receives it
A short list of named providers help us run Evelyst, each for the jobs listed here, and we don't sell your personal data to anyone.
6.1 We share Personal Data only with the following recipients, for the purposes stated:
- (a) Supabase (database and file storage in Singapore; server functions in the Supabase region nearest to the visitor): our database, sign-in and account emails, file storage, and the server functions that receive form entries and sign-ins. It holds all the data we store.
- (b) Railway (Singapore): runs the Analyst's server and its scheduled jobs, such as the Monday review and watches. It processes account data and Customer Data while handling requests, and keeps server logs.
- (c) OpenAI (United States ___ (missing: confirm OpenAI processing location from OpenAI's DPA (with F3))): the AI processing described in section 5.
- (d) Resend (United States): sends the Monday review, watch alerts, contact-form notifications to us, and other email we send from evelyst.com, such as waitlist updates. It processes the recipient's address and the email's content.
- (e) Cloudflare (global network): DNS for our domains, hosting the Sites and Evelyst POS, Web Analytics, Turnstile, and routing email sent to our addresses.
- (f) Google (United States): our email inbox. Messages sent to hello@, support@ and privacy@evelyst.com, and our notifications of contact-form messages, are forwarded to a Google (Gmail) mailbox, where we read and answer them. Those messages can include Customer Data.
- (g) Paddle (independent controller): as our reseller and Merchant of Record, Paddle handles checkout, payment, invoices and tax, and issues refunds, under its own privacy notice. Paddle decides how it uses the data it collects for those purposes.
6.2 The recipients in clause 6.1(a) to (f) act on our instructions under data processing terms. ___ (missing: confirm data processing terms with Supabase, Railway, Resend and Cloudflare) ___ (missing: Google terms or DPA; consumer Gmail has none, so move to Google Workspace or another inbox with a DPA before launch) For OpenAI, see clause 5.5. The current list of sub-processors, with what each one does and where, is at ___ (missing: the sub-processors page is not published in this build). We give notice of changes to it as the ___ (missing: the Data Processing Addendum page is not published in this build) describes.
6.3 We may also disclose Personal Data:
- (a) to the Customer and its users, according to their roles in the account, for Customer Data;
- (b) to courts, the National Privacy Commission and other authorities, where the law requires it or a valid legal order compels it;
- (c) to our professional advisers, such as lawyers and accountants, under a duty of confidentiality; and
- (d) to a buyer or successor of the business, if it is transferred, under the same protections as this Policy and with notice to you.
6.4 We don't sell Personal Data. We don't share it for advertising based on your activity across other websites, and we don't give or sell it to data brokers.
7 · International transfers
Our database is in Singapore, but some data is processed, and copies kept, in the United States and elsewhere, where local authorities may be able to reach it under their own laws.
7.1 Our database is stored in Singapore by Supabase, and the Analyst's server runs in Singapore on Railway.
7.2 Some Personal Data is processed, and in some cases kept, outside Singapore:
- (a) by OpenAI and Resend in the United States;
- (b) by Cloudflare on its global network, usually at a location near the visitor;
- (c) by Supabase's server functions, in the region given in clause 6.1(a);
- (d) by Google, for our email inbox;
- (e) by Paddle, as its privacy notice describes; and
- (f) by Evelyst itself, which works from the Philippines.
7.3 Data processed in another country is subject to that country's laws, and its courts, police or other authorities may be able to obtain access to it.
7.4 Under Section 21 of the Data Privacy Act, Evelyst remains responsible for Personal Data it transfers to its providers. We use contractual means to require a level of protection comparable to the Data Privacy Act (clause 6.2), and, for Personal Data transferred out of Singapore, protection comparable to Singapore's Personal Data Protection Act.
8 · How long we keep it
We keep each kind of data only as long as its rule here says, and after your account closes we keep your data 30 days so you can still ask for a copy, then delete it 30 days after closing, and from backups within 60 days of closing, except what the law makes us keep or we need for a legal claim.
8.1 We keep Personal Data as follows:
- (a) Account data: while your account is open. Cancelling a paid plan does not close your account and deletes nothing. To close your account, email privacy@evelyst.com or support@evelyst.com from the account owner's email address. We keep your account data and Customer Data for 30 days after your account closes, so you can still ask for a copy, and delete it from our live systems at the end of those 30 days, and from any backups within 60 days of closing. We tell you when it is done. If you asked for a copy in time (clause 8.1(l)), we send it before we delete. If no one signs in to an account with no active paid plan for 24 months, we email the owner, and if no one signs in within 60 days after that, we close the account and delete its data as above.
- (b) Customer Data (records, uploads, notes, targets, watches and Evelyst POS data): until the Customer deletes it where the Service allows (for example, undoing an import within 7 days, or deleting a note or a watch), asks us to delete it, or closes the account. It is then deleted as in clause 8.1(a).
- (c) Questions and answers: kept while the account is open, so that you can go back to them. A conversation you delete is hidden at once and removed from our systems within 30 days.
- (d) Original files and photos: not kept after they have been read (clause 3.6(b)).
- (e) Sign-in security records: 90 days from the attempt.
- (f) Usage and cost records: as account data, clause 8.1(a).
- (g) Data held by our AI provider: as OpenAI's terms provide (clause 5.5).
- (h) Server, delivery and security logs kept by our providers: for each provider's standard log period. ___ (missing: log retention at Railway, Supabase and Resend)
- (i) Billing records: Paddle keeps its records as its privacy notice and the law require. We keep our own records of subscriptions, payouts and invoices for as long as tax and accounting laws require; in the Philippines, generally five years from the deadline for filing the related return.
- (j) Waitlist entries: until you leave the list, or 12 months after the Service opens to the public if you haven't signed up by then, whichever comes first. When you leave the list, we delete your answers and keep only your email address on a do-not-email list, for as long as we send marketing email, so that we never write to you again.
- (k) Contact and support messages: 24 months after our last exchange, unless we need them for a legal claim.
- (l) Evelyst POS records: as the Customer instructs under the ___ (missing: the Data Processing Addendum page is not published in this build), and deleted as in clause 8.1(a) when the account closes. Keeping sales and Senior Citizen and PWD records for as long as the BIR requires is the restaurant's duty. A Customer that needs a copy of its Customer Data can ask for one at any time while its account is open, or within 30 days after it closes, by emailing privacy@evelyst.com or support@evelyst.com from the account owner's email address (clause 10.2).
- (m) Data on your device: stays in that browser until you or the browser clear it. On the Sites, what is kept in session storage (clause 3.1) is cleared when the tab is closed. Signing out of the Analyst removes the sign-in flag and any unsent question; display preferences and, on a till, the store details, open carts and last receipt stay until cleared (section 12).
- (n) Records of acceptance of our Terms and ___ (missing: the Data Processing Addendum page is not published in this build) (who accepted, when and which version): we will keep them while the account is open and for 3 years after it closes.
8.2 We don't keep Personal Data "just in case", or indefinitely for a use not yet decided.
8.3 The only exceptions to the deletion rules above are: (a) data the law requires us to keep; and (b) data we need to establish, exercise or defend a legal claim, kept only for as long as that need lasts. Billing records are kept by Paddle, and by us, as the tax rules require (clause 8.1(i)).
9 · Security and breaches
We use standard safeguards; if a breach of data we control needs reporting, we'll tell the regulator and the people affected within 72 hours as the law requires, and for data your business put in, we'll tell your business so it can act.
9.1 We protect Personal Data with organisational, physical and technical measures suited to the risk, including:
- (a) encryption in transit (HTTPS) between your browser and the Service;
- (b) access controls, with access inside Evelyst limited to the owner (clause 3.12);
- (c) row-level security in our database, so each Customer's account can reach only that Customer's data;
- (d) limits on failed sign-in attempts;
- (e) passwords stored only by our authentication provider, in hashed form; and
- (f) an encrypted sign-in cookie that scripts in the page cannot read.
9.2 No system is perfectly secure, and we can't guarantee that Personal Data will never be accessed without authority.
9.3 If a breach of Personal Data that we control (clause 2.1) requires notification, we will notify the National Privacy Commission and the affected data subjects within 72 hours of knowing, or reasonably believing, that it has occurred, as the Implementing Rules and Regulations of the Data Privacy Act require. We will also notify other regulators, such as Singapore's Personal Data Protection Commission, where their laws require it. For a breach affecting Customer Data, we will notify the Customer as the ___ (missing: the Data Processing Addendum page is not published in this build) describes, and help it notify the Commission and the people affected.
9.4 To report a security concern, email privacy@evelyst.com.
10 · Your rights
You can ask to see, correct, delete or take a copy of your data, or object to how we use it, by emailing privacy@evelyst.com; for data a business put in about you, we'll pass your request to that business, and you can always complain to the National Privacy Commission.
10.1 Under the Data Privacy Act, you have the right:
- (a) to be informed about how your Personal Data is processed;
- (b) to access it, including its sources, its recipients and how it is processed;
- (c) to have inaccurate or incomplete data corrected;
- (d) to object to processing, including for direct marketing;
- (e) to have it suspended, withdrawn, blocked, removed or destroyed (erasure);
- (f) to obtain a copy in an electronic, structured and commonly used format (portability);
- (g) to withdraw consent at any time, without affecting processing that took place before; and
- (h) to be compensated for damages caused by inaccurate, incomplete, outdated, false or unlawfully obtained data, or by unauthorised use of it.
10.2 How to exercise them. Email privacy@evelyst.com, from the email address we hold for you if you can. A person handles every request: the Service has no buttons yet to export your data or delete your account, so we do that by hand. We may ask for information to confirm your identity before acting. We don't charge for a request.
10.3 When we reply. We will reply within 30 days of receiving your request. If we need longer, we will tell you why within that time.
10.4 Customer Data. For data a business has put into the Service about you, we handle requests as described in clause 2.4.
10.5 Limits. We may decline or limit a request where the law allows, for example where we must keep records for tax purposes or where acting would reveal another person's data. If we do, we will tell you why.
10.6 Complaints. You may lodge a complaint with the National Privacy Commission of the Philippines (privacy.gov.ph), or with the data protection regulator where you live, such as Singapore's Personal Data Protection Commission. You are welcome to contact us first, but you don't have to.
10.7 Wherever you live. For data we control (section 2.1), we honour requests to access, correct or delete Personal Data from anyone, wherever they live, even where no law requires us to, subject to clause 10.5. For Customer Data, clause 2.4 applies.
11 · Marketing email
Joining the waitlist means one email a month while we build and one when we open, and every one has a link to leave the list.
11.1 We send marketing email only to people who have joined the waitlist. Entering your email address and pressing Join the waitlist is your consent to receive it; the line under the field ("One email a month while we build: what's done and what's next. No card required.") says what you will get. There is no separate checkbox. We keep a record of when you joined and the wording you saw.
11.2 While we build, we send one email a month about what's done and what's next, and one email when Evelyst opens.
11.3 Every marketing email has an unsubscribe link at the foot. You can also leave the list by replying or by writing to hello@evelyst.com. Leaving is free, needs no account or password, and is honoured promptly, within 10 business days at most.
11.4 We don't send cold email, we don't buy email lists, and we don't share our list with anyone except the providers that send it for us (section 6).
11.5 The Monday review, watch alerts, and account, billing, security and legal notices are service emails, not marketing. The Monday review and watch alerts carry a one-click unsubscribe link, and you can also switch the Monday review off in Settings. We send notices needed to run your account for as long as it stays open.
12 · Cookies and analytics
Our sites use no advertising or analytics cookies; the app uses a sign-in cookie, and your device keeps a few settings.
12.1 The Sites. Cloudflare Web Analytics counts visits without cookies and reports them to us only in aggregate. The Sites set no advertising or analytics cookies. If you choose a theme, the theme key in your browser's local storage remembers it. During a visit, session storage also holds the link tag and, after you join the waitlist, your email address, as clause 3.1 describes; your browser clears it when the tab is closed.
12.2 Turnstile. The waitlist and contact forms use Cloudflare Turnstile to block automated abuse. It runs in Managed mode. To do its check, Cloudflare processes technical data from your browser, such as your IP address.
12.3 Cloudflare's network. Cloudflare may set cookies that are strictly necessary to protect the Sites and Evelyst POS from automated abuse. ___ (missing: confirm whether Cloudflare sets any cookie on evelyst.com or pos.evelyst.com)
12.4 The Analyst. The Analyst sets one cookie, ev_session, on app.evelyst.com. It keeps you signed in, is encrypted, cannot be read by scripts in the page, and lasts 30 days or until you sign out. It is strictly necessary. The Analyst also keeps display preferences in your browser's local storage, such as theme, chart or table views, the selected data source and the date of your last visit, and keeps any question you have typed but not sent until you send it or sign out.
12.5 Evelyst POS. The till sets no cookies of its own. It uses the browser's local storage on the tablet as described in clause 3.10(h).
12.6 You can clear cookies and local storage in your browser at any time. If you block ev_session, you can't sign in to the Analyst.
12.7 We use no advertising cookies, tracking pixels or social media trackers.
13 · Do Not Track
We don't track you across other websites, so there's nothing for a Do Not Track signal to switch off.
13.1 We don't collect Personal Data about your online activities over time and across third-party websites. We therefore treat every visit the same, whether or not your browser sends a Do Not Track signal: there is no cross-site tracking either way.
13.2 We don't allow third parties to use the Sites or the Service to track your activities across other websites. There are no advertising, social media or tracking scripts on them. Cloudflare processes technical data on its network, which serves many websites, only to deliver and protect the Sites and to tell people from automated abuse; it does not use it for advertising.
14 · Children
Evelyst is for businesses run by adults; a restaurant may give till logins to staff under 18 where the law allows, and if we learn a child has given us their data directly, we delete it.
14.1 The Sites and the Service are for businesses. You must be 18 or older to join the waitlist, write to us or hold an owner account, and no one under 18 may use the Analyst. A restaurant may give Evelyst POS logins to staff under 18 where the law allows them to work (/terms clause 3.2). Their data is Customer Data, handled under the ___ (missing: the Data Processing Addendum page is not published in this build). Apart from that, we don't knowingly collect Personal Data from anyone under 18.
14.2 If we learn that we have collected Personal Data directly from someone under 18, through the waitlist, the contact form, email or an owner account, we will delete it.
15 · Where Evelyst is offered
Evelyst isn't offered in the European Economic Area, the United Kingdom or Switzerland.
15.1 Evelyst does not offer the Sites or the Service to people in the European Economic Area, the United Kingdom or Switzerland. We don't knowingly accept accounts or waitlist entries from people there, and we delete waitlist entries we learn come from there.
16 · Changes and date
If we change this policy in a way that matters, we'll email account owners and the waitlist at least 30 days before it takes effect, and post it here.
16.1 This Policy takes effect on ___ (missing: effective date). The date it was last updated is shown at the top of this page.
16.2 If we make a material change, we will email account owners and people on the waitlist at least 30 days before it takes effect. We will post other changes here with a new "last updated" date. Earlier versions are available on request.
16.3 Where a change needs your consent, we will ask for it and will not apply the change to you without it.