Privacy Policy
Last updated June 12, 2026
Crumb (“we”) is analytics software for independent food businesses. This policy explains what we collect, why, who helps us process it, and how you can see or delete it. Questions: crumbsupport@gmail.com.
What we collect
- Account info — the email and password you sign up with.
- Square data — when you connect Square, we read your sales, orders, line items, and customer records to power your dashboards. We never write to your Square account.
- Receipts & invoices you upload — the original photos/PDFs and the line items we read from them.
- What you enter — operating costs (rent, utilities, etc.) and team/payroll details you choose to add.
- Bank & card data (only if you connect it) — if you link a financial account through Plaid, we receive transactions and balances for the accounts you authorize, so they appear alongside your other spending. We do not store your bank login; that stays with Plaid.
How we use it
Solely to provide the service to you — dashboards, food/labor cost, price tracking, alerts, and the “Ask Crumb” assistant that answers questions about your own numbers. We do not sell your data, and we do not use it for advertising.
Who processes your data (subprocessors)
- Supabase — database, file storage, and authentication.
- Vercel — application hosting.
- Anthropic (Claude) — powers the assistant and reads your uploaded receipts. Data sent for processing is not used to train models.
- Square — the source of your sales data, by your authorization.
- Plaid — connects your financial accounts (only if you choose to). Plaid's handling of your data is governed by Plaid's privacy policy at plaid.com/legal.
How we protect it
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is restricted by database row-level security so each account sees only its own data, secrets are kept out of source code, and administrative accounts use multi-factor authentication.
How long we keep it & how to delete it
We keep your data while your account is active. You can delete everything at any time from Settings → Danger zone → Delete account, which permanently removes your stored data — Square records, uploaded receipts and files, costs, team, chats, and any connected-account data — and signs you out. Deletion is processed immediately and completes within 30 days across backups. You can also email us to request deletion.
Your consent
By creating an account and connecting your data sources, you consent to the collection, processing, and storage described here. Connecting a financial account additionally requires your explicit consent inside Plaid's secure connection flow.
We may update this policy as the product evolves; we'll change the date above when we do.