Effective August 5, 2026
Privacy policy
This policy explains the information Gordon needs to create and deliver a restaurant menu audit.
Information we collect
We collect the answers, restaurant details, email address, website links, menu files, and other material you submit. We also store audit outputs, account and authentication identifiers, payment identifiers, and limited security and diagnostic logs.
Stripe processes card details. Gordon does not receive or store full card numbers.
How we use information
We use information to identify the restaurant, create and deliver the audit, process payment and refunds, send service messages, prevent abuse, diagnose failures, and improve the product.
Menu and restaurant source material may be processed by AI services to extract facts, generate analysis, create a redesign, and check the rendered result. We do not send card data to AI providers.
Service providers
Gordon relies on Vercel for hosting, Supabase for database, storage, and authentication, OpenAI for AI generation, Google Places for restaurant identity, Cloudflare Turnstile for abuse prevention, Stripe for payments, Resend for email, and Trigger.dev for background workflow execution. These providers process information for the services they supply under their own terms and privacy commitments.
Retention and deletion
Gordon keeps information only as long as reasonably needed to provide the service, maintain the customer workspace, resolve disputes, and meet accounting or legal obligations. Our v1 operating targets are seven days for abandoned unverified requests, 30 days for unpaid verified requests and uploads, and 30 days after delivery for source uploads. Purchased audit artifacts may remain available while the workspace is active.
Cleanup may be completed manually during v1. You may request access, correction, or deletion by replying to a Gordon email. Some payment and transaction records may be retained where required for tax, accounting, fraud prevention, or dispute handling.
Security and choices
We use access controls, signed links, encryption in transit, and restricted service credentials. No online service can guarantee absolute security. Authentication cookies are used to keep you signed in; Turnstile and our infrastructure may also use security signals to distinguish legitimate requests from abuse.
Gordon is intended for United States business customers and is not directed to children.
Questions or requests? Reply to any email Gordon sent you and include your audit reference. You can also return to the audit page.