Data Processing Addendum Summary
This page summarizes Covey's processor/service-provider posture for business customer content. A signed standalone DPA may be provided later for eligible business customers.
1. Roles
For restaurant customer content, menu/order data, customer communications, and connected account data that a business submits to Covey, the business is generally the controller or owner. Covey generally acts as a processor or service provider to provide the requested service.
2. Processing purpose
Covey processes customer content to operate accounts, order pages, payment confirmation, billing, security, support, diagnostics, legal compliance, and approved workflows.
3. Service providers
Covey uses service providers such as Cloudflare, Supabase, Stripe, Google OAuth, and other providers listed in Subprocessors where enabled.
4. Transfers
Covey is operated from the United States. Data may be processed in the United States or other countries where providers operate. Where required, Covey relies on appropriate contractual and legal transfer mechanisms.
5. Deletion and export
Business users may request export or deletion of eligible data. Some records may be retained for legal, tax, fraud-prevention, backup, dispute, and security purposes.
6. Sensitive data
Do not submit regulated medical records, government IDs, private keys, payment credentials, or other highly sensitive data unless Covey explicitly supports that category in writing.