INTERNAL TEAM SERVICE · BENETTI’S ONLY
Privacy Policy
Updated 3 October 2026
This policy covers the Pan & Plans public website and the Benetti’s Kitchen internal team service. The operator is Maurizio Incardona; privacy and support contact: panandplans@gmail.com. Access is currently limited to authorised Benetti’s team members. There are no paid subscriptions or public restaurant registrations.
Adults-only access
Access is restricted to authorised Benetti’s team members aged 18 or over. The owner must confirm adulthood before approving a team member. Under-18s must not use the application or its AI features. This admission procedure relies on owner confirmation; it does not independently verify identity or age and does not collect a date of birth.
What we collect and why
- Accounts: name, email address, Firebase user ID, email-verification status and sign-in information, to authenticate users and handle access requests. Password authentication is managed by Firebase; restaurant owners cannot view your password.
- Restaurant access: restaurant membership, invitations, approval status, role and kitchen station, to give the appropriate team access.
- Kitchen work: recipes, menus, prep lists, orders, stock and pricing, team shifts, HACCP records, handovers, chat, optional photos, voice messages and uploaded documents. These are shared within the relevant workspace according to its permissions.
- Activity: author names, timestamps, presence and typing indicators, used for collaboration and activity history.
- Technical information: service providers receive connection information such as IP addresses and browser details when delivering the site, fonts, authentication and database services.
Only add information needed for kitchen work. Do not upload identity documents, payment-card details, medical records or sensitive employee records. Restaurant owners should tell staff what information they enter and who can see it.
Who can access it
Approved or invited members can access their restaurant’s shared work. Workspace owners manage membership. Benetti’s has a separate Firebase project and sign-in; registration alone does not grant access. Its ingredient prices and shifts require approved Admin access and an Executive Chef or Head Chef role. The separate private development workspace permits only its existing verified owner account. This Benetti’s team entry requires verified email and restaurant-owner approval. This initial release is for Benetti’s only; other restaurants and subscriptions are not offered.
Authorised service administrators may need access for support and security. Google/Firebase processes information to run hosting, authentication and databases. The configured Realtime Databases are in Singapore. Authentication, Gmail delivery, AI and other Google provider services may process information outside Australia, including Singapore and the United States. These services are not represented as storing all information in Australia. Processing locations vary by service and provider arrangements; we will update this policy when those arrangements change.
Files, AI and notifications
Text extraction from supported document imports runs in your browser. Attached files and confirmed imported records are saved to the restaurant database. Photos and voice messages you choose to post are shared with that team. Benetti’s photo scanning sends your selected image to Google Gemini through Firebase AI Logic only when you choose Read photo. Review and select the extracted text before saving it to your restaurant. The app does not store scan photos. Data handling depends on the Google Cloud project used for the AI request. Under Google’s unpaid Gemini terms, submitted content and responses may be used to improve its services and may be reviewed by people. For API requests through a project associated with an active billing account, Google’s paid-service terms state that prompts and responses are not used to improve its products. Limited abuse-prevention processing still applies. These different terms apply according to the project used for each AI feature; the app does not promise that every AI request uses paid-service data handling. Do not submit personal, sensitive or confidential information. See Google’s Gemini terms. App Check/reCAPTCHA processes browser and network signals to prevent abuse. AI wine pairing is enabled in the private Benetti’s workspace. It sends dish names, descriptions, ingredients and preparation, together with the saved wine list and tasting notes, to Google through Firebase AI Logic. Two recommendations per dish are saved with generation metadata and reused while the dish and wine-list inputs remain unchanged; opening the saved recommendations does not generate a new AI request. Weekly drinks can be entered manually. Push notifications, where enabled, use an optional browser subscription that can be revoked in the browser. Delivery depends on browser support, permission and the configured backend.
Staff access emails: for a new access request, a scheduled service checks the pending request, verified account and membership status. It emails the applicant’s name and email to panandplans@gmail.com using Gmail. Checks run every 15 minutes. Private delivery records contain a hashed account identifier, status and timestamp to prevent repeat notifications; they do not grant access. The operator keeps these records while the account/request remains relevant and can remove them when processing an account-deletion request. A copy of the notification is also held in the operator’s Gmail mailbox and is reviewed for deletion when the request or related account is closed, subject to a justified recordkeeping need.
Browser storage and tracking
Firebase keeps sign-in state in browser storage. The app stores preferences such as theme, station, sound and alert settings. An explicitly selected local preview stores workspace data in IndexedDB; online restaurant data is stored in Firebase. The demo uses sample data. No advertising pixels, behavioural analytics or session-replay integration were found in the reviewed app code. See Cookies & browser storage for details.
Retention, access and deletion
Private daily backups of both Realtime Databases are stored in Singapore. Backup objects expire after 30 days and remain recoverable through soft delete for a further 7 days. This does not erase active kitchen records. Firebase Authentication accounts and objects held outside the databases are not included. A deployment-verified copy of database rules is included and must be refreshed when rules change. Backup recovery has been tested in a separate local environment; it does not constitute a guaranteed recovery time.
There is currently no automatic expiry for saved kitchen records, uploaded documents or access requests. Revoking membership blocks future authorised access but does not erase previously downloaded copies or contributions. Restaurant backups are user-requested JSON downloads containing the profile, workspace records and supported kitchen data, including uploaded attachments and saved wine recommendations. Account credentials, membership permissions, invitation links and push subscriptions are excluded. Import creates a separate restaurant owned by the importing account. Downloaded backups may contain team information; the person keeping a copy controls its storage and deletion. For this internal service, record retention is handled by the operator and restaurant owner according to continued kitchen use, safety recordkeeping and any applicable legal requirements. We do not claim a fixed automatic deletion period for live records. You can ask us to explain the retention of a particular record and request deletion of information no longer needed.
Email panandplans@gmail.com to request access to your personal information, correction, export or account deletion. Requests are handled manually; there is no complete self-service account-deletion screen. We confirm your identity proportionately, coordinate with the restaurant owner, and explain the outcome and any recordkeeping reason for retaining information. We aim to acknowledge requests within 7 days and respond within 30 days; if more time is needed, we will explain why. Do not email passwords or identity documents unless a secure verification method has been agreed.
Security and updates
We use encrypted HTTPS connections and database access rules, and test restaurant isolation. These measures do not amount to a guarantee that every risk has been eliminated. We assess reported security incidents, take steps to contain them and notify affected people and relevant authorities where required. We update this policy as features and processing arrangements change; material changes will be communicated through the service or email.
Operator and contact
The operator for this internal Benetti’s phase is Maurizio Incardona. For privacy, access or correction requests, complaints and support, email panandplans@gmail.com. We review requests, confirm identity where needed and explain any recordkeeping or legal reason that prevents deletion. Commercial subscriptions and other restaurants are not offered in this phase.
For privacy complaints, first email panandplans@gmail.com so we can investigate. If unresolved, you may contact the Office of the Australian Information Commissioner, where the complaint falls within its jurisdiction. This policy is informed by OAIC guidance on privacy policies and Google’s Gemini API terms.