Privacy Policy
§ 01Introduction and Scope
GSM Consultants Inc. ("GSM," "we," "us," or "our"), a corporation organized under the laws of the State of New York, develops and operates SBOS, a cloud-based restaurant and hospitality operations platform (the "Platform"). The Platform provides restaurants, hospitality operators, and food-service businesses (collectively, "Merchants" or "Operators") with integrated functionality for point-of-sale processing, employee and payroll management, attendance and time tracking, customer relationship management, order management, reporting and analytics, payment processing, QuickBooks Online integration, and related business operations.
This Privacy Policy ("Policy") describes:
- The categories of personal information GSM collects and receives through the Platform;
- The purposes for which personal information is processed;
- How personal information is shared, retained, and protected;
- The legal rights available to users and data subjects; and
- GSM's obligations and the Merchant's obligations with respect to data governance.
This Policy applies to: (i) Merchant personnel who access the Platform, including managers, administrators, employees, payroll staff, and any other authorized users ("Users"); (ii) end customers of Merchants whose information may be entered into the Platform by Merchant personnel; (iii) visitors to gsmnyc.com; and (iv) recipients of SMS communications transmitted through the Platform.
This Policy does not apply to the information practices of third-party services integrated with the Platform, including but not limited to QuickBooks Online, PAX payment hardware, or third-party payment processors. Users should review the privacy policies of such third parties directly.
§ 02Definitions
As used in this Policy, the following terms have the meanings set forth below:
§ 03Data Controller and Data Processor Relationships
3.1 GSM as Data Processor
With respect to personal information about Merchant Users and end Customers that is entered into, generated by, or transmitted through the Platform, GSM acts as a Data Processor. GSM collects, stores, and processes such data exclusively on behalf of, and pursuant to the documented instructions of, the applicable Merchant. The Merchant, as Data Controller, retains ownership of and responsibility for that data, including responsibility for the lawfulness of its collection and use.
3.2 Merchant as Data Controller
Each Merchant that deploys the Platform is independently responsible as the Data Controller for all personal information it causes to be collected, entered, or processed through the Platform. Merchants determine: (i) which employees are enrolled in the system; (ii) what Customer information is collected at the point of sale; (iii) how long data is retained; (iv) how Customer data is used for marketing or operational purposes; and (v) compliance with applicable employment, tax, and consumer privacy laws.
3.3 GSM as Independent Data Controller
GSM acts as an independent Data Controller with respect to: (i) information collected through gsmnyc.com for business development or support purposes; (ii) platform usage analytics and performance telemetry collected to improve the Platform; (iii) security and audit log data collected for fraud prevention, system security, and legal compliance; and (iv) information provided by Merchants in connection with their commercial relationship with GSM.
§ 04Information We Collect
4.1 Employee and User Information
| Data Element | Purpose | Storage |
|---|---|---|
| Full name | Identity verification, payroll records, audit attribution | Encrypted cloud database |
| Username | Authentication and access control | Encrypted cloud database |
| Mobile phone number | OTP authentication, SMS notifications | Encrypted cloud database |
| Email address | Account communications, OTP delivery, notifications | Encrypted cloud database |
| Password (hashed) | Authentication — never stored in plaintext | Bcrypt hash, encrypted cloud database |
| Employee role / permissions | Role-based access control (RBAC) | Encrypted cloud database |
| Login timestamps and session records | Security audit trail, compliance logging | Encrypted cloud database |
| Attendance and clock-in/clock-out records | Time tracking, payroll calculation | Encrypted cloud database |
| Payroll data (wages, hours, deductions, tax withholdings) | Payroll processing, reporting, QuickBooks sync | Encrypted cloud database |
| Device information (model, OS, terminal ID) | Hardware compatibility, payment routing, diagnostics | Encrypted cloud database |
| Security and audit log entries | Fraud prevention, dispute resolution, compliance | Encrypted cloud database |
4.2 Customer Information
Customer personal information is entered into the Platform solely by Merchant personnel. GSM does not independently collect Customer information. The following Customer data elements may be present in the Platform at Merchant's direction:
| Data Element | Purpose | Storage |
|---|---|---|
| Customer name (optional) | Order association, customer profile | Encrypted cloud database (Merchant account) |
| Customer phone number (optional) | Receipt delivery, OTP, loyalty programs | Encrypted cloud database (Merchant account) |
| Customer email address (optional) | Digital receipts, communications | Encrypted cloud database (Merchant account) |
| Order history and transaction records | Customer profile, reporting, repeat-order convenience | Encrypted cloud database (Merchant account) |
4.3 Transaction and Payment Information
| Data Element | Purpose | Stored by GSM? |
|---|---|---|
| Last 4 digits of payment card | Receipt display, transaction reference, dispute resolution | Yes |
| Card brand (Visa, Mastercard, Amex, etc.) | Receipt display, reporting | Yes |
| Transaction authorization code | Audit trail, dispute resolution | Yes |
| Transaction amount, tip, tax, and surcharges | Financial records, reporting | Yes |
| Payment method type (cash, card, split) | Reporting, reconciliation | Yes |
| Full Primary Account Number (PAN) | NOT collected or stored by GSM | NEVER |
| CVV / CVC code | NOT collected or stored by GSM | NEVER |
| Magnetic stripe data | NOT collected or stored by GSM | NEVER |
| PIN data | NOT collected or stored by GSM | NEVER |
4.4 Information We Do Not Collect
GSM does not collect the following through the Platform:
- GPS coordinates or precise geolocation data;
- Device contact lists or address book data;
- Biometric identifiers — if device-level biometric authentication is enabled, such data is processed exclusively within the device hardware and is never transmitted to GSM's systems;
- Social media account credentials or profile data;
- Advertising identifiers, cross-app tracking data, or behavioral advertising profiles;
- Health or medical information;
- Government-issued identification numbers (e.g., Social Security Numbers), except where a Merchant independently configures its payroll module to capture such data, in which case the Merchant is the Data Controller for such information.
§ 05How We Use Personal Information
5.1 Platform Operations and Service Delivery
- Authenticating Users and enforcing role-based access control;
- Processing, routing, and fulfilling orders within the Merchant's operation;
- Facilitating payment transactions through PAX hardware and third-party payment processors;
- Generating receipts, invoices, bills, and financial documents;
- Managing employee schedules, attendance records, and time-tracking data;
- Processing payroll calculations and supporting payroll reporting;
- Synchronizing accounting and payroll data with QuickBooks Online at Merchant's direction;
- Delivering transactional and informational SMS and email notifications;
- Supporting customer management features deployed by Merchants.
5.2 Security, Fraud Prevention, and Legal Compliance
- Detecting, investigating, and preventing unauthorized access, fraudulent transactions, and security incidents;
- Maintaining audit logs for regulatory compliance, tax recordkeeping, and dispute resolution;
- Responding to valid legal process, subpoenas, court orders, and requests from law enforcement agencies;
- Enforcing GSM's agreements with Merchants and Users;
- Protecting the rights, property, and safety of GSM, Merchants, Users, and the public.
5.3 Platform Improvement and Analytics
- Analyzing aggregated, de-identified usage data to improve Platform functionality, performance, and reliability;
- Diagnosing technical issues and optimizing system performance;
- Developing new product features based on usage patterns.
GSM does not use personal information of Users or Customers for cross-context behavioral advertising, third-party marketing, or the sale of personal information to data brokers.
§ 06SMS Communications and TCPA Compliance
6.1 SMS Consent and Opt-In
The Platform transmits SMS messages to Users and, in limited circumstances, to Customers at Merchant's direction, for transactional and operational purposes, including OTP authentication codes, account alerts, payroll notifications, and order-related communications. By providing your mobile phone number in connection with the Platform, you expressly consent to receive such messages:
By providing your mobile phone number, you consent to receive transactional and informational SMS messages from GSM Consultants Inc. regarding your SBOS account. Message frequency varies. Message and data rates may apply. Reply STOP to opt out. Reply HELP for assistance. Contact info@gsmnyc.com for support.
6.2 Regulatory Compliance
GSM's SMS communications are conducted in compliance with the Telephone Consumer Protection Act (TCPA), 47 U.S.C. § 227, the CTIA Messaging Principles and Best Practices, and applicable carrier A2P 10DLC requirements. Specifically:
- All SMS messages are transactional or informational in nature and are sent pursuant to an established business relationship or prior express written consent;
- GSM does not transmit unsolicited commercial text messages through the Platform;
- Recipients may opt out at any time by replying STOP; GSM will honor opt-out requests within the time period required by applicable law and CTIA guidelines;
- Recipients may request assistance by replying HELP and will receive a response identifying the sender and providing contact information;
- GSM's A2P 10DLC messaging campaigns are registered with applicable carriers through a registered Campaign Service Provider;
- Message and data rates charged by a recipient's wireless carrier may apply; GSM does not control such rates.
6.3 Opt-Out
To opt out of SMS notifications, a User may: (i) reply STOP to any SMS message; (ii) modify notification preferences within the SBOS platform settings; or (iii) contact GSM at info@gsmnyc.com. Opting out of SMS notifications may affect receipt of OTP authentication codes required to access the Platform, in which case the User should contact their system administrator to configure an alternative authentication method.
§ 07Information Sharing and Disclosure
GSM does not sell, rent, lease, or trade personal information to any third party for monetary or other valuable consideration. GSM does not share personal information with third parties for their independent marketing or advertising purposes. Personal information may be shared only in the following limited circumstances:
| Recipient | Information Shared | Legal Basis / Purpose |
|---|---|---|
| Merchant / Operator | All operational, payroll, attendance, customer, and transaction data within Merchant's account | Merchant is the Data Controller; GSM processes on Merchant's behalf |
| PAX Payment Hardware | Payment transaction instructions only; transmitted locally via encrypted TCP/IP | Payment processing; Sensitive Payment Data never enters GSM software |
| Third-Party Payment Processors | Transaction authorization requests; GSM receives only masked card data in response | Payment settlement and authorization |
| Intuit (QuickBooks Online) | Payroll, accounting, and financial data at Merchant's configuration and direction | Accounting integration; shared only when Merchant enables QBO sync |
| Cloud Infrastructure Providers | Encrypted operational data stored in secure cloud environments | Platform hosting and data storage under confidentiality agreements |
| SMS Delivery Providers | Mobile phone numbers and message content for OTP and transactional SMS | Authenticated SMS delivery; providers bound by data processing agreements |
| Professional Advisors | As reasonably necessary | Legal advice, audit, and compliance functions under confidentiality obligations |
| Law Enforcement / Courts | In response to valid legal process | Compliance with applicable law; GSM will notify Merchants where legally permissible |
| Successor Entities | Business operational data | Merger, acquisition, or asset sale; successor bound by this Policy |
Any third-party service providers engaged by GSM to process personal information are required by contract to: (i) process personal information only as instructed by GSM; (ii) implement appropriate technical and organizational security measures; and (iii) not disclose personal information to unauthorized parties.
§ 08QuickBooks Online Integration
8.1 Nature of Integration
The Platform offers optional integration with Intuit's QuickBooks Online accounting service. This integration is enabled exclusively at the direction and configuration of the Merchant and enables automated synchronization of payroll records, accounting entries, financial reporting data, and related business operations data between the Platform and the Merchant's QuickBooks Online account.
8.2 Data Shared with QuickBooks Online
When the QuickBooks Online integration is enabled by a Merchant, the following categories of data may be transmitted to QuickBooks Online:
- Payroll data, including employee compensation records, hours worked, and deduction records;
- Sales transaction summaries and revenue data;
- Accounts receivable and accounts payable entries;
- Tax-related financial records;
- General ledger entries and reconciliation data.
8.3 Merchant Responsibility
The Merchant is solely responsible for configuring and enabling the QuickBooks Online integration, for ensuring that it has the legal right to share applicable data with Intuit, and for reviewing and complying with Intuit's Privacy Policy and Terms of Service. GSM's transmission of data to QuickBooks Online constitutes processing performed on behalf of and at the direction of the Merchant.
8.4 Purpose Limitation
Data transmitted to QuickBooks Online through the Platform integration is used exclusively for the following permitted purposes: accounting, payroll processing, financial reporting, reconciliation, tax compliance, and related business operations. GSM does not use QuickBooks integration data for any other purpose.
§ 09Merchant Responsibility
GSM's role is that of a software provider and Data Processor. The Merchant, as Data Controller, is solely responsible for the following:
9.1 Employee Data
- Obtaining all legally required consents or satisfying all applicable legal bases for the collection, processing, and use of employee personal information, including payroll data, attendance records, and biometric data where applicable;
- Complying with all applicable employment, labor, payroll, tax withholding, and benefits administration laws and regulations;
- Providing employees with all notices required by applicable privacy and employment law, including notice that the Merchant uses GSM's Platform to process employee data;
- Configuring the Platform's employee permissions and access controls appropriately for each User's role.
9.2 Customer Data
- Ensuring that any Customer personal information entered into the Platform is collected with appropriate notice and, where required, consent;
- Complying with applicable consumer privacy laws, including the New York SHIELD Act, the California Consumer Privacy Act (where applicable), and other applicable state or federal consumer privacy statutes;
- Responding to Customer requests for access to, correction of, or deletion of their personal information;
- Establishing and maintaining the Merchant's own privacy policy and making it available to Customers.
9.3 Platform Configuration
- Maintaining the security of Merchant administrator credentials and access control configurations;
- Ensuring that only authorized personnel are granted access to the Platform;
- Notifying GSM promptly upon becoming aware of any unauthorized access to or use of the Platform.
GSM is not responsible for the Merchant's data governance practices, the lawfulness of the Merchant's collection of personal information, or the Merchant's compliance with applicable law.
§ 10Data Security
GSM implements reasonable technical, administrative, and physical security measures designed to protect personal information against unauthorized access, disclosure, alteration, and destruction, consistent with the requirements of the New York SHIELD Act (N.Y. Gen. Bus. Law § 899-bb) and applicable industry standards.
10.1 Technical Safeguards
- All API communications are encrypted using HTTPS / TLS 1.2 or higher;
- Authentication tokens (JWT) are stored using encrypted device storage backed by platform-level secure storage mechanisms;
- User passwords are stored exclusively as salted cryptographic hashes; plaintext passwords are never stored or logged;
- OTP authentication codes are time-limited and single-use;
- Cloud databases containing personal information are encrypted at rest;
- Payment card data is processed exclusively through PCI PTS-certified PAX hardware; raw card data never enters the SBOS application layer;
- Application data on deployed terminal devices is stored in sandboxed, access-controlled directories.
10.2 Administrative Safeguards
- Role-based access controls limit data access to personnel whose job responsibilities require it;
- GSM maintains audit logs recording user access, administrative actions, and security-relevant events;
- Third-party service providers with access to personal information are required to maintain appropriate security standards by contract.
10.3 Incident Response
In the event of a security breach affecting personal information, GSM will notify affected Merchants and, where required by applicable law, affected individuals and regulatory authorities, in accordance with the timelines and requirements of the New York SHIELD Act and other applicable breach notification laws.
10.4 Limitations
No security system is impenetrable. While GSM takes commercially reasonable steps to protect personal information, GSM cannot guarantee that unauthorized third parties will never be able to defeat its security measures. Merchants and Users assume some risk in providing personal information in connection with the Platform.
§ 11Data Retention
GSM retains personal information for the period reasonably necessary to fulfill the purposes described in this Policy, comply with applicable law, resolve disputes, and enforce its agreements.
| Data Category | Retention Period | Governing Rationale |
|---|---|---|
| User authentication tokens (JWT) | Until logout, session expiration, or account termination | Security; minimal retention principle |
| Employee records (names, roles, contact info) | Duration of employment plus as required by applicable employment and tax law (typically 3–7 years) | New York Labor Law; IRS requirements |
| Payroll records | Minimum 6 years from date of record creation | New York Labor Law § 195; federal tax law |
| Attendance / time-tracking records | Minimum 6 years | New York Labor Law requirements |
| Payment transaction records (masked) | Minimum 18 months, extendable for dispute resolution | PCI DSS requirements; dispute resolution |
| Customer records (when collected by Merchant) | As directed by Merchant as Data Controller, subject to applicable law | Merchant retention policies; consumer privacy law |
| Audit and security logs | Minimum 12 months; longer where required for compliance or active investigations | Security; legal compliance |
| QuickBooks integration data | As maintained by Intuit; governed by Intuit's data retention policies | Accounting and tax compliance |
| Platform analytics (de-identified) | Indefinitely in aggregated, de-identified form | Product improvement |
Upon termination of a Merchant's subscription, GSM will, at Merchant's written request, provide an export of its operational data in a machine-readable format within a commercially reasonable time period, and will thereafter securely delete or anonymize Merchant's personal information, except to the extent retention is required by applicable law.
§ 12U.S. State Privacy Rights
12.1 New York Residents — New York SHIELD Act
GSM's data security practices are designed to comply with the New York Stop Hacks and Improve Electronic Data Security (SHIELD) Act (N.Y. Gen. Bus. Law §§ 899-aa, 899-bb). The SHIELD Act requires businesses that own or license computerized data including private information of New York residents to implement a reasonable data security program. GSM's security measures are described in Section 10 above.
New York does not currently have a comprehensive consumer privacy statute analogous to California's CCPA. New York residents who are employees or authorized Users of a Merchant may exercise data access and correction rights by contacting the Merchant administrator or by contacting GSM directly at info@gsmnyc.com.
12.2 California Residents — CCPA/CPRA
To the extent the California Consumer Privacy Act of 2018 (as amended by the California Privacy Rights Act of 2020) applies to GSM's processing of personal information of California residents, California residents have the following rights:
- Right to Know: The right to request disclosure of the categories and specific pieces of personal information collected, sources, business purposes, and categories of third parties with whom GSM shares information;
- Right to Delete: The right to request deletion of personal information, subject to applicable exceptions;
- Right to Correct: The right to request correction of inaccurate personal information;
- Right to Opt-Out of Sale or Sharing: GSM does not sell or share personal information as those terms are defined under the CCPA;
- Right to Non-Discrimination: You have the right not to receive discriminatory treatment for exercising your CCPA rights.
12.3 Other U.S. States
Residents of states that have enacted comprehensive consumer privacy legislation (including Virginia, Colorado, Connecticut, Utah, Texas, Florida, and others) may have similar rights, subject to applicable exemptions. GSM will honor valid requests exercised under applicable state law. Where a Merchant is the Data Controller for the applicable data, GSM will direct requests to the Merchant or assist the Merchant in responding, as appropriate.
12.4 How to Exercise Privacy Rights
To exercise any applicable privacy rights, please contact: info@gsmnyc.com or visit gsmnyc.com. GSM will respond to verifiable requests within the timeframes required by applicable law. GSM may require verification of your identity before processing a request.
§ 13Children's Privacy
The SBOS Platform is an enterprise business software application designed exclusively for use by adult business operators, managers, employees, and other authorized commercial personnel. The Platform is not directed at children. GSM does not knowingly collect, solicit, or process personal information from individuals under the age of thirteen (13) as defined by the Children's Online Privacy Protection Act (COPPA), 15 U.S.C. §§ 6501–6506, or individuals under the age of sixteen (16) under applicable state law.
If GSM becomes aware that personal information from a minor has been inadvertently collected through the Platform, GSM will take prompt steps to delete such information. If you believe that a minor's personal information has been collected through the Platform, please contact GSM immediately at info@gsmnyc.com.
§ 14International Users
The SBOS Platform is designed, marketed, and deployed exclusively within the United States. GSM's cloud infrastructure and data processing operations are located in the United States. GSM does not intentionally target or market the Platform to users outside the United States.
If you are accessing the Platform from outside the United States, please be aware that your personal information will be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Platform from outside the United States, you consent to the transfer of your information to the United States.
GSM does not represent that the Platform complies with the General Data Protection Regulation (EU/UK GDPR), the Personal Information Protection and Electronic Documents Act (PIPEDA), or any other non-U.S. privacy regulatory framework. Merchants seeking to deploy the Platform in jurisdictions outside the United States should consult qualified legal counsel.
§ 15Internal Business Use of Information
GSM uses personal information for the following internal business purposes:
- Account management, customer support, and technical assistance for Merchants;
- Billing, invoicing, and subscription management in connection with Merchant agreements;
- Platform performance monitoring, error detection, and technical diagnostics;
- Training and quality assurance activities related to Platform operations;
- Legal compliance, audit, regulatory reporting, and enforcement of GSM's agreements;
- Internal reporting and business performance analytics (using aggregated or de-identified data where possible).
GSM does not use Merchant or Customer personal information for cross-platform targeted advertising, behavioral profiling, or any purpose materially inconsistent with the purposes described in this Policy.
§ 16Cookies and Tracking Technologies
The SBOS Platform application, as deployed on PAX terminal hardware, does not use browser-based cookies or cross-site tracking technologies. The Platform may use session tokens and local device storage for authentication and offline data caching purposes, as described in Section 4 above.
The GSM website at gsmnyc.com may use standard web cookies and analytics tools to measure website traffic and improve user experience. These cookies do not track users across third-party websites for advertising purposes. Visitors to gsmnyc.com may configure their browsers to decline or delete cookies; doing so may affect certain website functionality.
§ 17Links to Third-Party Services
The Platform may reference or provide access to third-party services, including QuickBooks Online, PAX payment processing infrastructure, and third-party payment processors. This Policy does not apply to the information practices of such third-party services. GSM encourages Merchants and Users to review the privacy policies of any third-party services they access in connection with the Platform. GSM is not responsible for the privacy practices or content of third-party services.
§ 18Changes to This Privacy Policy
GSM reserves the right to update or modify this Policy at any time to reflect changes in the Platform's features, applicable law, or GSM's data practices. The "Last Updated" date at the top of this Policy reflects the most recent revision.
GSM will provide notice of material changes by posting the updated Policy on gsmnyc.com and, where feasible, by notifying Merchants via email or in-Platform notification. For Merchants, continued use of the Platform following the effective date of a material change constitutes acceptance of the revised Policy. Merchants should review this Policy periodically and communicate relevant updates to their Users.
§ 19Contact Information
For questions, concerns, or requests regarding this Privacy Policy, GSM's data practices, or your rights with respect to personal information, please contact:
GSM Consultants Inc.
GSM will make commercially reasonable efforts to respond to all privacy-related inquiries in a timely manner. For requests related to personal information maintained by a Merchant, GSM may direct you to the applicable Merchant as the Data Controller.