Privacy policy

Vorsa is operated by Innovative App Concepts LLC. Effective 28 August 2026.

Vorsa is restaurant operations software. Restaurants use it to run checklists, track inventory, cost recipes, and process supplier invoices. This policy explains what we collect, what we do with it, and what we will never do with it.

We do not sell or share your data, or your customers’ data, with anyone for their own purposes. We do not use it to train models. We do not use one restaurant’s data to serve another.

Who is responsible for what

Two organisations handle data here and the split matters.

The restaurant decides what goes into Vorsa — which staff have accounts, which suppliers are recorded, what is photographed and uploaded. They are responsible for that content and for who they give access to.

Innovative App Concepts LLC operates the software and stores the data on the restaurant’s behalf. We are responsible for keeping it separated, available, and used only for running the service.

If you are an employee of a restaurant using Vorsa and want your personal data corrected or removed, ask your employer first — they control the account. If that does not resolve it, contact us at support@vorsasystems.com.

What we collect

Account data. Name, work email, job role and position, and the location you work at. Enough to know who you are and what you may see.

Operational data. The work itself: completed checklists, line checks, inventory counts, recipes, waste entries, equipment records, supplier invoices and the documents they came from.

Technical data. Sign-in times, IP address and browser for sessions, and errors the app encounters. Used to keep accounts secure and to fix faults.

Messages. Where a restaurant enables text messaging to suppliers, we record what was sent, to whom, and whether it was delivered.

What we access in your QuickBooks, and why

Connecting QuickBooks Online is optional. Nothing happens until someone at your restaurant authorises it, and it can be disconnected at any time.

We read your chart of accounts and your vendor list. Both are needed to map what you buy onto the accounts you book it against — a supplier invoice cannot become a bill without knowing which account each line belongs to, and QuickBooks identifies accounts and vendors by internal ID rather than by name.

We write exactly one kind of record: bills, into Accounts Payable. Nothing else. We do not create or edit vendors, accounts, customers, invoices, payments, or journal entries. We do not modify or delete a bill after creating it. The software has no capability to do any of those things, and that is enforced in our build rather than left to policy.

A bill is created only when a person clicks to post it. There is no automatic posting, no scheduled job, and no bulk action. One invoice, one deliberate click, by someone with permission to authorise spend.

Every bill we create is tagged so you can identify it: it carries your own invoice number as its reference and a memo naming the Vorsa record it came from.

Disconnecting, and what happens to your data

You can disconnect QuickBooks from inside Vorsa, or from inside QuickBooks itself. Either way we stop having access immediately, and we delete the stored authorisation.

Bills already posted to QuickBooks stay in QuickBooks. They are your accounting records and they belong to you — removing them is your decision, made in QuickBooks, not ours to reverse.

Disconnecting does not delete anything else. Your invoices, recipes and counts remain in Vorsa because they are your operating records, not QuickBooks’ data.

If you close your Vorsa account, we delete your data within 60 days, except where we are required to keep something longer by law. You can request an export of your data at any time before then.

Who else sees it

We use a small number of service providers to run Vorsa. Each receives only what it needs to do its job, and none may use your data for its own purposes:

Cloudflare (hosting and network), Amazon Web Services and Cloudflare R2 (file storage), Resend (email), Telnyx (text messages, where enabled), Anthropic (reading photographed invoices, where enabled), and Intuit (QuickBooks, where connected).

Where invoice photographs are read automatically, the image and the text on it are sent to Anthropic to extract the line items and are not used to train their models.

We will disclose data if legally compelled. If that happens and we are permitted to tell you, we will.

Keeping restaurants separate

Each restaurant’s data is isolated at the database level, not merely by application code. A query that fails to identify which restaurant it is asking about returns nothing rather than returning somebody else’s records.

Access within a restaurant is controlled by role, and by field: someone who can see a supplier’s phone number cannot necessarily see financial contacts or pay information.

Security

Data is encrypted in transit. Files are stored in a private bucket reachable only through the application, which re-checks permission on every access. Passwords are hashed and never recoverable. Backups are encrypted and their restoration is tested on a schedule rather than assumed.

If a breach affects your data we will tell you promptly and directly, with what we know and what we are doing, rather than waiting until we know everything.

Children

Vorsa is workplace software and is not directed at children. Where a restaurant employs people under 18, their accounts are created and controlled by their employer.

Changes

If we change this policy in a way that affects what we do with your data, we will tell account holders before it takes effect rather than only updating the date at the top.


Questions about this document: support@vorsasystems.com