SageOps SAGE OPS Sign In

Privacy Policy

Effective Date: January 2025 · Version 1.0

Thyme 2 Play LLC ("T2P," "we," "us") describes how it collects, uses, and protects information when you use the RGP Platform. We understand the sensitivity of restaurant operator data, including employee information, financial records, and customer details.

Quick Summary: We collect account info, operational data you input, integration data, and usage data. We use it to provide service, improve the Platform, communicate, and comply with law. We share only with service providers — no data sales. We use encryption, access controls, and notify of breaches within 72 hours. You can access, export, correct, delete, and opt-out of marketing. AI assists, you decide — always review AI outputs.

1. Information We Collect

1.1 Account Information

Upon subscription, we collect business name, contact information, email addresses for account administrators, and billing information (processed through Stripe — we do not store full payment details).

1.2 Operational Data You Provide

You may input employee data (names, contact information, roles, schedules, compensation, performance records), menu data, financial data, customer data, and operational data.

1.3 Data from Integrations

With your authorization, data flows from POS systems (Toast, Square), scheduling systems (Sling, 7Shifts), and other configured integrations.

1.4 Usage Data

We automatically collect login times, session duration, features accessed, error logs, performance data, device information, and browser information.

1.5 AI Interactions

Queries and responses are processed to provide service. Conversations may be used to improve AI (anonymized). We do not use your specific business data to train models for other customers.

2. How We Use Information

2.1 To Provide the Service

Maintaining access, processing transactions, sending invoices, providing customer support, and delivering requested reports and analytics.

2.2 To Improve the Platform

Analyzing usage patterns (aggregated/anonymized), identifying bugs, developing features, and improving AI accuracy.

2.3 To Communicate

Service announcements, billing notifications, support responses, and product news (with opt-out available).

2.4 To Protect and Comply

Preventing fraud, enforcing Terms of Service, and complying with legal obligations.

3. Information Sharing

3.1 Data Sale Policy

We do not sell, rent, or trade your personal or business information to third parties.

3.2 Service Providers

We share data with the following vendors to operate the Platform:

  • Railway: Hosting infrastructure (all platform data, encrypted)
  • Neon: Database infrastructure (PostgreSQL, encrypted at rest)
  • Stripe: Payment processing (billing information)
  • Resend: Email delivery (email addresses, message content)
  • Anthropic: AI processing (query content, no PII transmitted)

These providers are contractually bound to protect your data and use it only for the specified purposes.

3.3 Integrations You Authorize

Data flows between the Platform and authorized third-party services according to your configuration and their privacy policies.

3.4 Legal Requirements

Information may be disclosed if required by law, court order, government request, or to protect rights, property, or safety.

3.5 Business Transfers

If acquired or merged, information may transfer to the new owner with user notification.

4. Data Security

4.1 Technical Measures

  • Data encrypted in transit (TLS) and at rest
  • Access controls and authentication
  • Regular security assessments
  • Secure cloud infrastructure

4.2 Operational Measures

  • Limited employee access to customer data
  • Confidentiality agreements
  • Security training
  • Incident response procedures

4.3 Your Role

You are responsible for keeping credentials secure, using strong passwords, controlling account access, and reporting suspected breaches promptly.

4.4 Breach Notification

If we discover a data breach affecting your information, we will notify you within 72 hours with details and remediation steps.

5. Data Retention

5.1 Active Accounts

Data is retained while subscriptions are active and for a reasonable period afterward to support business continuity and compliance.

5.2 After Termination

You have 30 days after subscription ends to export your data. After 30 days, operational data is deleted from active systems. Some data persists in backups for up to 90 days. Aggregated, anonymized data may be retained indefinitely.

5.3 Legal Holds

Data may be retained longer if required for legal proceedings, audits, or regulatory compliance.

6. Your Rights

6.1 Access and Export

You can access and export data at any time through Platform export features.

6.2 Correction

You can correct inaccurate data directly or by contacting us.

6.3 Deletion

You can request data deletion by contacting us. Some data may be retained per Section 5.

6.4 Portability

Data exports are provided in standard formats (CSV, JSON, PDF).

6.5 Opt-Out

You can opt out of marketing communications. Service-related communications cannot be opted out while subscribed.

7. California Privacy Rights

California residents have CCPA rights including:

  • The right to know what personal information is collected
  • The right to delete personal information
  • The right to opt-out (we do not sell personal information)
  • Non-discrimination for exercising these rights

Contact: [email protected]

8. Employee and Customer Data

8.1 Your Employees

You are the data controller for employee information. You are responsible for providing employee notices, obtaining consents, responding to requests, and complying with employment privacy laws. We process employee data as a service provider.

8.2 Your Customers

Similar responsibilities apply for customer information stored in the Platform.

9. AI and Automated Processing

9.1 How AI Works

The Platform uses AI to provide operational assistance, generate documents, answer questions, and make recommendations.

9.2 Human Oversight Required

AI can make mistakes. AI outputs are suggestions requiring your review and validation, especially for HR decisions, financial calculations, compliance matters, and customer communications.

9.3 No Fully Automated Decisions

We do not make significant decisions about you or your employees based solely on automated processing. AI assists; humans decide.

9.4 AI Data Usage

Queries are processed to generate responses. Anonymized interaction patterns may improve AI. Your specific business data is not used to train models for other customers.

10. Cookies and Tracking

10.1 Essential Cookies

We use cookies for authentication, session management, security features, and user preferences.

10.2 Analytics

We may use analytics tools to understand usage. Data is aggregated and does not identify individuals.

10.3 No Advertising Tracking

We do not use advertising cookies or sell data to advertisers.

11. Children's Privacy

The Platform is designed for business use and is not intended for individuals under 18. We do not knowingly collect information from children.

12. International Data

12.1 Data Location

The Platform is hosted in the United States. By using the Platform, you consent to the transfer and processing of your data in the US.

12.2 International Users

Data from outside the US will be transferred to and processed in the US, which may have different data protection laws.

13. Changes to This Policy

We may update this policy periodically, notifying you by email to account administrators and Platform notice. Continued use constitutes acceptance.

14. Contact Us

Thyme 2 Play LLC
Email: [email protected]
Website: sageops.io

Terms of Service: sageops.io/terms

Terms of Service Privacy Policy

© 2026 Thyme 2 Play LLC. All rights reserved. Built in Los Angeles, CA.