Effective Date: July 29, 2026
This Privacy Policy explains how The Fmly Group, LLC, doing business as “Fried”(“Fried,” “we,” “us,” or “our”), collects, uses, discloses, and protects information in connection with the Fried restaurant-intelligence service (the “Service”).
Fried is a United States–only business-to-business (B2B) service offered to restaurants and their operators. The Service connects to a restaurant's point-of-sale (“POS”) system, computes analytics from the restaurant's own data, and delivers insights through a daily/weekly email (“Morning Char”) and a web dashboard.
If you have questions about this Policy or our data practices, contact us at [email protected] or by mail at 201 Broad St. Unit 2508, Stamford, CT 06901.
1. A Note on the Two Kinds of Data We Handle
Because Fried is a B2B service, it is important to distinguish two categories of information:
- Business Data— operational data belonging to the restaurant, derived from the restaurant's connected POS system (for example, sales totals, transaction counts, item-level sales, labor and timing data, and analytics we compute from them). Business Data generally describes the operation of a business, not an identifiable consumer. The restaurant owns its Business Data; our handling of it is governed primarily by our Terms of Service and any applicable data-processing terms.
- Personal Information— information that identifies, relates to, or could reasonably be linked to an individual. For Fried, this primarily means the account and profile information of the operator or staff member who signs up for and uses the Service (for example, name, email address, and Google profile details when Google sign-in is used).
This Policy focuses on Personal Information. Where Business Data contains or is linked to Personal Information, we treat that linked information consistently with this Policy.
2. Information We Collect
2.1 Account Information (provided by you)
When an operator creates an account or contacts us, we collect:
- Name and email address.
- Restaurant/business name and the location(s) being connected.
- Login credentials or, where Google sign-in is used, an authentication token rather than a password.
- Support communications and any information you choose to provide to us.
2.2 Google Profile Information (Google OAuth)
If you sign in with Google, we receive limited profile information from Google's OAuth service — typically your name, email address, Google account identifier, and profile image. We use this only to create and authenticate your Fried account. We do not receive your Google password.
2.3 POS-Derived Business Data (via secure connection)
When you connect a supported POS provider through its secure connection method (OAuth or credential entry, depending on the provider), you authorize that provider to share business and transaction data with us. We use this data to compute analytics and generate your insights. This is primarily Business Data, as described in Section 1.
2.4 Usage Information (collected automatically)
When you use the dashboard or open Morning Char emails, we may collect limited technical and usage information such as IP address, browser/device type, pages or features accessed, and basic email-engagement signals (e.g., whether an email was opened), to operate, secure, and improve the Service.
2.5 Payment Information (collected by Stripe, not by Fried)
Subscriptions are billed through Stripe. When billing is active, payment card information is collected and processed directly by Stripe under Stripe's own terms and privacy policy. Fried never receives or stores full payment card numbers (PANs). We may receive limited billing metadata from Stripe (e.g., subscription status, last four digits, billing contact) to manage your account.
We do not intentionally collect sensitive categories of personal information (such as health, biometric, or precise geolocation data), and the Service is not directed to children (see Section 9).
3. How We Use Information
We use the information described above to:
- Create, authenticate, and manage your account (including Google sign-in).
- Connect to your POS provider and compute analytics from your Business Data.
- Generate and deliver your Morning Char insight emails and dashboard.
- Provide customer support and respond to your requests.
- Operate, secure, monitor, troubleshoot, and improve the Service, including preventing fraud and abuse.
- Manage billing and subscriptions (via Stripe) once billing is active.
- Send service-related communications and, where permitted, product updates.
- Comply with legal obligations and enforce our agreements.
Honesty principle. Fried only reports numbers and insights that can be derived from your own connected data. We do not fabricate metrics, and we do not guarantee any business outcome from using the Service.
4. AI Processing Disclosure
To generate the narrative, plain-language portions of your insights, Fried uses a third-party large-language-model provider, Anthropic. The data we send to Anthropic for narrative generation is limited to computed metrics, summary figures, your top-selling menu items, and your restaurant's name for context. We do not send your login or account identity, individual customer records, or staff personal information to Anthropic.
Under Anthropic's commercial API terms, Anthropic does not use the content we send to train its models. Anthropic may retain API inputs and outputs for a limited period for trust-and-safety purposes, as described in its terms, and not for model training. Anthropic is named as a sub-processor on our Sub-processor List.
5. How We Share Information — Sub-processors and Third Parties
We do not sell your Personal Information (see Section 8). We share information only as follows:
- Service providers / sub-processors that help us operate the Service. These currently include, among others, Supabase (database, authentication, hosting), Vercel (hosting), Anthropic(AI narrative generation — aggregated, non-PII; see Section 4), Resend (email delivery), Stripe (payments), Google (OAuth sign-in), and the connected POS vendors that you authorize.
- A current, itemized list of sub-processors — including each provider's role and processing location — is maintained on our separate Sub-processor List page. We reference that page rather than restating every provider inline, and we update it as our vendors change.
- Legal and safety disclosures. We may disclose information where required by law, subpoena, or legal process, or to protect the rights, safety, or property of Fried, our customers, or others.
- Business transfers. If Fried is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
Sub-processors are authorized to use information only as needed to provide their services to us.
6. Cookies and Tracking
Fried currently uses only minimal, essential cookies and similar technologies needed to operate the dashboard — for example, to keep you signed in and maintain your session. We do not currently use third-party advertising trackers, cross-site tracking, or behavioral advertising cookies. If we introduce additional analytics or tracking in the future, we will update this Policy and provide any disclosures or controls required by law.
Because we do not engage in cross-context behavioral advertising, we do not currently process opt-out preference signals (such as Global Privacy Control) for advertising purposes; if that changes, we will honor applicable signals as required.
7. Data Retention
We retain Personal Information for as long as your account is active and as needed to provide the Service, and afterward only as necessary for legitimate business purposes (such as security, dispute resolution, and legal compliance).
- Account information: retained while your account is active; deleted or de-identified after account closure, unless a longer period is required by law.
- POS-derived Business Data: retained while the connection is active and used to compute analytics; on disconnection or account closure, deleted or de-identified.
- Usage logs: retained for security and operational purposes.
- Billing records (via Stripe): retained as required for tax, accounting, and legal purposes.
8. Your Privacy Rights (California Residents — CCPA/CPRA)
Fried operates in the United States and is aware of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (“CCPA/CPRA”). While our customers are businesses, the operator's personal account information may constitute Personal Information of a California resident. To the extent the CCPA/CPRA applies, eligible individuals have the right to:
- Know / Access— request the categories and specific pieces of Personal Information we have collected about you, the sources, the purposes, and the categories of third parties with whom we share it.
- Delete— request deletion of Personal Information we have collected about you, subject to legal exceptions.
- Correct— request correction of inaccurate Personal Information.
- Opt out of “sale” or “sharing” — Fried does not sell or share Personal Informationas those terms are defined under the CCPA/CPRA, so there is no sale/share to opt out of. If this ever changes, we will provide a “Do Not Sell or Share My Personal Information” mechanism.
- Non-discrimination— we will not discriminate against you for exercising any of these rights.
How to exercise your rights. Submit a request to [email protected]. We will verify your request (for example, by confirming control of the account email) before acting on it, and respond within the timeframes required by law. You may use an authorized agent where permitted.
9. Children's Privacy
The Service is a B2B product intended solely for use by businesses and their authorized adult representatives. It is not directed to children, and we do not knowingly collect Personal Information from anyone under 16. If you believe a child has provided us information, contact [email protected] and we will take appropriate steps to delete it.
10. Security
We use reasonable administrative, technical, and organizational measures designed to protect Personal Information, including encryption in transit, access controls, and reliance on reputable infrastructure providers (such as Supabase and Vercel). Payment card data is handled entirely by Stripe and never stored by Fried. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the “Effective Date” above and provide notice through the Service or by email where appropriate. Your continued use of the Service after an update means you accept the revised Policy.
12. Contact Us
The Fmly Group, LLC d/b/a Fried
201 Broad St. Unit 2508, Stamford, CT 06901
Privacy inquiries: [email protected]