Privacy Policy
Last updated: April 8, 2026
1. Who We Are
Expo is a product of Carbonaro Media LLC, a Michigan limited liability company. Expo is an SMS-based AI business assistant built for independent restaurant owners. When we say "Expo," "we," "us," or "our," we mean Carbonaro Media LLC.
2. Information We Collect
We collect the following categories of information:
Account Information
- Name, email address, and mobile phone number (provided during signup)
- Restaurant name, type, and operating hours
- Password (stored as a secure hash — we never see or store your plain-text password)
Point-of-Sale Data (via Square)
- Sales totals, order details, and item-level data
- Labor and timecard information (clock-ins, hours worked)
- Payment breakdowns (cash, card, tips)
Bank Data (via Plaid)
- Account balances and recent transactions (read-only access)
- Deposit verification data
- We cannot move, transfer, or withdraw your money
Invoice Data
- Photos of supplier invoices sent via text message
- Extracted line items, prices, quantities, and vendor names
SMS Messages
- Text messages you send to and receive from Expo
- Message content is used to provide AI-powered responses and is stored to maintain conversation context
Billing Information
- Payment processing is handled entirely by Stripe — we do not store your credit card number, bank account details, or other payment credentials
3. How We Use Your Information
- To power the AI business assistant — your data is used to generate personalized, context-aware responses to your questions
- To generate daily morning recaps and smart business alerts
- To track and analyze supplier invoices and detect price changes
- To reconcile deposits between your POS and bank account
- To provide labor cost analysis and staffing insights
- To process your subscription billing
- To send you SMS messages including AI responses, recaps, alerts, invoice confirmations, and support replies
4. Third-Party Services
We use the following third-party services to operate Expo:
- Square — to access your point-of-sale data (sales, orders, labor)
- Plaid — to access your bank account data (balances, transactions) in read-only mode
- Twilio — to send and receive SMS text messages
- Anthropic (Claude) — to power AI-generated responses and analysis
- Stripe — to process subscription payments
- Google Cloud Vision — to read and extract text from invoice photos
- Amazon Web Services (AWS) — to host our servers and store invoice images securely
Each of these services has its own privacy policy governing how they handle data. We encourage you to review their policies.
5. What We Do Not Do
- We do not sell your personal information to anyone
- We do not share your data with advertisers or marketing companies
- We do not use your data to market third-party products to you
- We do not share your SMS consent or phone number with third parties for their marketing purposes
6. SMS and Messaging
- Message frequency varies based on your usage — conversational messages are sent when you text us, daily recaps are sent once per morning, and alerts are sent as needed
- Standard message and data rates may apply depending on your carrier and plan
- You can opt out of all messages at any time by texting STOP
- For help, text Contact Support and our team will reach out to you
- Your consent to receive messages is not shared with any third party
7. Data Retention
We retain your data for as long as your account is active. If you cancel your subscription, your data is kept for 30 days in case you return, after which it is permanently deleted. You may request immediate deletion of your data at any time by contacting us.
8. Data Security
We take the security of your data seriously. All connections to our servers are encrypted using TLS/HTTPS. Passwords are hashed using bcrypt. API tokens for Square, Plaid, and other integrations are stored securely and never exposed to the frontend. Access to your data requires authentication, and we enforce ownership checks to prevent unauthorized access.
9. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate information
- Request deletion of your data
- Export your data
- Opt out of SMS messages at any time
To exercise any of these rights, contact us at carbonaromedia@gmail.com.
10. Children
Expo is not directed at individuals under the age of 13. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal information, we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via SMS or through our website. Your continued use of Expo after changes are posted constitutes your acceptance of the updated policy.
12. Contact Us
If you have questions about this Privacy Policy or your data, contact us at:
Carbonaro Media LLC
Email: carbonaromedia@gmail.com