ProfitPlate

Privacy Policy

Last updated: 2026-09-05

This page explains what personal data the ProfitPlate application (at plate.storium.work) collects, where it lives, and how long it is kept. What this marketing website itself collects is covered separately, in the last section below — the answer is nothing.

What we collect, and where it lives

ProfitPlate uses Clerk to hold your actual identity: your email address, and whether you've verified it. Our own application database keeps only a thin mirror of that — your Clerk user ID, your email address, an optional display name, when you last signed in, and which shops you belong to and your role in each.

If your shop subscribes, Stripe holds the billing side: the Owner's billing email, your card details, and your subscription and invoice history. Beyond a basic record that a subscription exists, we don't duplicate any of that in our own database.

We never see your card details

Card payments happen entirely on Stripe's own hosted checkout page — there is no card number, expiry or CVC field anywhere on ProfitPlate's own pages, and our servers never receive or store card data. That's a genuine technical fact, not just a policy promise: the code has nowhere for a card number to go.

Where your data is stored — including if you're in Taiwan

ProfitPlate's database runs on a DigitalOcean server in Sydney, Australia. Application logs are stored in AWS CloudWatch, also in Sydney, and kept for 90 days. Backups are stored in Cloudflare R2 with an Oceania location hint — a hint, not a guaranteed residency, since Cloudflare does not contractually promise which region any given backup lands in. Backups are kept for 30 days.

If you're a restaurant in Taiwan, this means your personal data is stored and processed in Australia, outside Taiwan. That's a genuine cross-border transfer of personal data, and we're stating it plainly here rather than leaving it for you to infer from a list of vendors.

Who else handles your data

We use a small number of outside providers to run ProfitPlate: Clerk for sign-in and identity, Stripe for payments, DigitalOcean to host the application and database, Cloudflare for content delivery, security filtering and backup storage, and AWS CloudWatch for logs. We don't use any email delivery provider — ProfitPlate has none.

Email

ProfitPlate doesn't send email of any kind — no marketing email, no newsletter, and no mailing list, because the product simply has no way to send mail. The only email you'll ever receive about your ProfitPlate account is Stripe's own billing mail — receipts, failed-payment notices and the like — sent directly by Stripe.

Logs

When you use ProfitPlate, our servers log request details for debugging and reliability. Before a log line is written, any field whose name matches password, token, secret, email, authorization, auth, key, jwt, card, cvc or cvv is blanked out. Your user ID and Clerk ID, however, are recorded on every request — those two aren't blanked out, and because they identify you, our logs are not anonymous.

Change history

For changes to your shop's data — ingredients, preps, dishes, shop settings, production plans and stock counts — ProfitPlate keeps a before-and-after record of the change itself. Right now, only some of the actions that can change this data also record who made the change; we don't yet attribute every change to a specific person, and we won't claim otherwise.

Signing in

Under ProfitPlate's current configuration, signing in uses a one-time code sent to your email rather than a password. That's a setting in our identity provider (Clerk), not a guarantee built into ProfitPlate's own code — so it describes how sign-in works today, not a permanent promise about how it will always work.

How long we keep your data

For shops that have never subscribed to ProfitPlate, the account's data may be deleted after roughly six months of inactivity — but this applies only to shops that have never subscribed: a shop that has subscribed even once is permanently exempt from this deletion, no matter how long it later goes unused.

Where this applies, it happens in two steps about three months apart: the shop is first marked inactive — nothing is removed yet at that point, and the shop can still be restored — and only in the second step would the underlying data actually be removed. Even if that second step happens, some records are excluded from it altogether: your account record, our billing history, and Stripe's own customer and invoice records are never deleted this way.

There is no warning email before any of this, because ProfitPlate doesn't send email at all. The only warning you'll ever see is a countdown shown if you sign back in while your shop is approaching this point — which makes this page one of only two places you'll ever be told about it. Please read it now rather than counting on a reminder.

Access and deletion requests

To ask what personal data ProfitPlate holds about you, or to ask for it to be corrected or deleted, contact systech202@gmail.com.

This marketing website

This page — and every page on this marketing website — collects nothing about you. There's no analytics, no cookies, no tracking script and no form anywhere on this site. Everything above describes the ProfitPlate application itself, not this website.