Privacy Policy

Last updated August 31, 2026

This policy describes how the Shootz Admin Dashboard (the “Dashboard”), operated by Shootz at shootz.fyi, collects and uses information. The Dashboard is an internal tool used by Shootz staff to run the restaurant business. It is not a consumer product, it has no public sign-up, and accounts are created by invitation only.

Who this policy covers

The people whose information appears in the Dashboard are Shootz staff and, in aggregate, Shootz guests. Access is restricted to authorized employees and contractors of Shootz. If you are a restaurant guest looking for the policy that governs ordering and marketing, that is a separate policy published on our guest-facing website.

Information we process

Account information

When an administrator invites you, we store your name, work email address, assigned role, and location assignments. Authentication is handled by Clerk; if you sign in with Google or Slack, we receive your basic profile from that provider in order to establish the session.

Business operations data

The Dashboard aggregates operational data from the systems Shootz runs on — point of sale, scheduling and time tracking, online ordering, guest feedback, marketing platforms, and accounting. This includes sales, labor, scheduling, and marketing performance records.

Usage information

We keep standard server and application logs, including IP address, browser type, and pages accessed, to operate and secure the service.

How we use information

  • To operate, secure, and support the Dashboard.
  • To produce internal reporting on sales, labor, marketing, and guest experience.
  • To publish marketing content we own to accounts Shootz controls (see the YouTube section below).
  • To meet legal, accounting, and tax obligations.

We do not sell personal information, and we do not use the data in the Dashboard to build advertising profiles of individuals.

Use of YouTube API Services

The Dashboard uses YouTube API Services to publish Shootz’s own marketing videos to a YouTube channel that Shootz owns and controls. By connecting a channel to the Dashboard, you agree to be bound by the YouTube Terms of Service. Google’s handling of your information is described in the Google Privacy Policy.

What we access

An administrator connects a channel through Google’s OAuth 2.0 consent screen, granting the youtube.force-ssl scope. With that authorization the Dashboard can upload videos to the connected channel, read the metadata and public statistics of videos it uploaded, and change the privacy status of those videos.

What we store

  • OAuth tokens — the access and refresh tokens for the connected channel, held encrypted in our database’s secret vault and never exposed to browsers or third parties.
  • Channel identity — the channel ID and title, so the Dashboard can show which channel is connected.
  • A publishing record — for each video we upload: its title, description, tags, privacy status, upload status, the YouTube video ID, the source file name, who requested it, and timestamps.

What we do not do

  • We do not collect or store information about YouTube viewers, their watch history, or their activity.
  • We do not access channels other than the one an administrator explicitly connects.
  • We do not sell, rent, or transfer YouTube data to any third party, and we do not use it for advertising or targeting.
  • We do not use YouTube data to train machine-learning models, and we do not combine it with data from other sources to profile individuals.

Retention and deletion

OAuth tokens are deleted from our systems immediately when a channel is disconnected. The publishing record is retained as an operational record of what we posted and can be deleted on request by contacting us at the address below.

Revoking our access

You can revoke the Dashboard’s access to your YouTube data at any time, in either of two ways:

  • In the Dashboard — an administrator can use the Disconnect control on the YouTube settings page, which revokes the token with Google and deletes it from our systems.
  • In your Google Account — visit the Google security settings page and remove this application’s access.

Other third-party services

The Dashboard integrates with services Shootz uses to run the business, including Toast, 7shifts, Restaurant365, Lunchbox, Ovation, Meta, Google, Slack, and Customer.io. Each processes data under its own agreement with Shootz. We share information with these providers only as needed to operate the business.

How we protect information

Access requires an invited account and is limited by role, so users see only what their role permits. Credentials and API tokens are stored encrypted in a dedicated secret vault. Connections are encrypted in transit. Administrative actions taken through the Dashboard’s automation tools are logged.

Your rights

Depending on where you live, you may have the right to request access to, correction of, or deletion of your personal information, and to object to certain processing. To exercise any of these rights, contact us at the address below and we will respond as required by applicable law.

Changes to this policy

We may update this policy from time to time. When we do, we will revise the “Last updated” date at the top of this page.

Contact us