Last updated: April 27, 2026
Privacy Policy
MERIS is built for restaurant owners who share sensitive financial data with us. We take that responsibility seriously. This policy explains — in plain English — exactly what we collect, why, and how we protect it.
What We Collect
We collect only what we need to run MERIS and nothing more:
- Account info — your name and email address when you sign up.
- Square POS data — sales transactions, labor records, and your product catalog, synced via the Square API.
- Bank account data via Plaid — account balances and transaction history from the bank accounts you choose to connect.
- Usage data — how you interact with the app (page views, feature usage) to help us improve the product.
How We Use Your Data
Your data is used exclusively to power MERIS for you:
- To calculate your business health metrics and risk scores.
- To generate AI-powered insights, forecasts, and trend analysis.
- To provide personalized recommendations for your restaurant.
We never sell your data to anyone. We never share your raw financial data with third parties. Full stop.
Plaid Data Practices
MERIS uses Plaid to securely connect your bank accounts. Here is exactly what that means:
- We only access account balances and transaction history — nothing else.
- We never see or store your bank login credentials. Plaid handles authentication directly with your bank.
- Plaid has its own privacy policy that governs how they handle your data. You can review it at plaid.com/legal.
- You can disconnect your bank account from MERIS at any time in Settings.
Data Retention
- We keep your data for as long as your account is active.
- Transaction data is retained for up to 2 years to support trend analysis and forecasting.
- If you delete your account, all of your data is permanently and irreversibly deleted within 30 days.
- You can request data deletion at any time by emailing support@meris.business.
Data Security
We take security seriously:
- All data is encrypted in transit using HTTPS/TLS.
- Data is stored in secure cloud infrastructure (Supabase) with row-level security so only you can access your records.
- Your Square and Plaid access tokens are encrypted at rest.
- We conduct regular security reviews and dependency scanning to stay ahead of vulnerabilities.
Your Rights
You are in control of your data:
- Access your data anytime through the MERIS dashboard.
- Request a full export of all data we hold on you.
- Request deletion of your account and all associated data.
- Disconnect Square or Plaid at any time from the Settings page — no lock-in.
To exercise any of these rights, email us at support@meris.business.
Changes to This Policy
If we make significant changes to this privacy policy, we will notify you by email before the changes take effect. Continued use of MERIS after that point means you accept the updated policy.
Minor updates (like fixing typos or clarifying language) may be made without notice.
© 2026 MERIS
support@meris.business