Privacy Policy

Last updated: July 27, 2026

This Privacy Policy explains how Proxie Studio ("we", "us") collects, uses, and shares information through SessionPilot OPS - both the web app at app.sessionpilot.nl and the "Session Pilot Ops" mobile app for Android and iOS (together, the "Service"). SessionPilot OPS is a restaurant operations platform used by restaurant owners and managers ("Employers") to manage their staff ("Employees"). If you're an Employee, your Employer decides to use this Service and controls the account it creates for you.

1. Who is responsible for your data

For most of the information described below - staff profiles, schedules, attendance, payroll, chat, and similar day-to-day operational data - your Employer (the restaurant) is the data controller. We act as their data processor: we host and run the Service on their behalf, following their instructions, and we don't use that data for our own independent purposes. If you have questions about data your Employer has entered about you, start with your manager or owner.

For account and billing information belonging to the Employer itself, and for data we collect to operate, secure, and improve the Service (see Section 6), Proxie Studio is the data controller.

2. Information we collect

2.1 Account & profile

  • Name, phone number, profile photo, role/job title, employment status
  • Login email (owners/managers) or an employer-issued employee ID (staff without email)
  • Password (stored hashed by our authentication provider - we never see it in plain text)

2.2 Employment & payroll data

  • Hourly rate, hours worked, computed pay, currency, and payslip history
  • Where your Employer chooses to collect it: your national personal identification number (e.g. a Swedish personnummer or similar), bank account details, and a contact email used solely to send you a self-service link to enter that information
  • Clock-in/clock-out timestamps, breaks, and the branch/location you clocked in at

2.3 Communications & content you create

  • Chat messages and photos you send to colleagues within the Service
  • Announcements, comments, reactions, and photos posted by managers/staff
  • Incident reports, including descriptions and photos
  • Checklist, task, SOP, and training-course activity and completion records

2.4 Device & app permissions (mobile app)

The mobile app may request the following device permissions, only used for the stated purpose:

  • Camera / microphone - to attach photos or use video features within chat, incidents, or training, when you choose to
  • Photos / storage - to attach an existing photo to a message, announcement, or incident report
  • Notifications - to show you push notifications (see 2.5)

2.5 Push notifications

If you allow notifications, the mobile app registers a device token with Firebase Cloud Messaging (a Google service) so we can send you notifications - for example, a new chat message or announcement. We store this token against your account so we know which devices to notify; it doesn't identify you to Google beyond what's inherently necessary to deliver the notification to your device.

2.6 Technical & usage data

We automatically log standard technical data needed to run the Service securely - IP address, browser/device type, and timestamps of requests. The web app uses a session cookie to keep you signed in; we don't use advertising or cross-site tracking cookies.

3. How we use information

  • To provide the Service: scheduling, attendance, payroll, checklists, chat, announcements, training, and reporting
  • To send operational notifications (push, email) you or your Employer have opted into
  • To generate AI-assisted operational summaries for managers (see Section 5) from aggregated recent activity
  • To secure the Service, prevent abuse, and debug issues
  • To comply with legal obligations (e.g. payroll and tax record-keeping)

4. Legal bases for processing (EEA/UK users)

Where GDPR or UK GDPR applies, we and/or your Employer rely on:

  • Performance of a contract - to run the core scheduling/attendance/payroll features of the Service
  • Legal obligation - for payroll, tax, and employment-record requirements
  • Legitimate interests - for security, fraud prevention, and improving the Service
  • Consent - for push notifications and any optional camera/microphone/photo access, which you can withdraw at any time in your device settings

5. Who we share information with

We share information only as needed to run the Service:

  • Your Employer - managers/owners at your restaurant can see the employment data relevant to running their business
  • Infrastructure providers - our database, authentication, and file storage run on self-hosted Supabase, on a server we operate with our hosting provider, OVH SAS, located in Brussels, Belgium
  • Firebase Cloud Messaging (Google) - to deliver push notifications to the mobile app
  • Google Gemini API - to generate the optional AI operations summary shown to managers, from a short window of aggregated recent activity
  • Resend - to deliver transactional emails (invitations, password resets, scheduled reports)
  • Legal/compliance - if required to comply with a legal obligation, or to protect the rights, property, or safety of the Service, our users, or the public

We do not sell personal data, and we do not share it with third parties for their own advertising purposes.

6. Data retention

We retain data for as long as your Employer's account is active. After an Employee leaves or an Employer closes their account, we retain employment, attendance, and payroll records for as long as required by the tax, accounting, and labor law that applies to that restaurant (this is often several years - for example, Swedish bookkeeping law generally requires 7 years), after which we delete or anonymize them. Chat messages, photos, announcements, and other day-to-day operational content are kept only for as long as the restaurant's account is active, unless we're legally required to keep it longer.

7. Security

We use industry-standard safeguards: encrypted connections (HTTPS/TLS) between your device and our servers, database-level row-level-security policies that restrict each account to the data it's authorized to see, and access controls limiting who can reach production systems and credentials.

8. Your rights

Depending on where you live, you may have the right to:

  • Access the personal data we/your Employer hold about you
  • Correct inaccurate data
  • Request deletion, subject to legal retention requirements
  • Restrict or object to certain processing
  • Receive a copy of your data in a portable format
  • Withdraw consent (e.g. for push notifications) at any time
  • Lodge a complaint with your local data protection authority

To exercise any of these rights, contact your Employer first for employment data, or reach us directly at enquiries@weareproxie.com.

9. International data transfers

Our infrastructure runs on servers located in Brussels, Belgium (EU), operated by our hosting provider, OVH SAS. Where a sub-processor (such as Google, for Firebase Cloud Messaging or the Gemini API) processes data outside the EU/EEA, we rely on that provider's applicable safeguards, such as the EU Standard Contractual Clauses.

10. Children's privacy

The Service is intended for use by restaurant staff and management and is not directed at children. Where local labor law permits younger workers to be employed, their Employer is responsible for ensuring appropriate consent and safeguards are in place before adding them to the Service.

11. Changes to this policy

We may update this policy from time to time. We'll update the "Last updated" date above, and for material changes we'll take reasonable steps to notify Employers.

12. Contact us

Proxie Studio
H.M-107 Jamalpur Colony, 141010, Ludhiana, Punjab, India
enquiries@weareproxie.com

Terms of Use