This Privacy Policy explains how Liftoff S.R.L. ("Liftoff", "we", "us"), the company that operates Oventab, collects, uses, and shares information when you visit our website, create an account, or use the Oventab platform (the "Service").
Liftoff is the data controller for the personal data processed through the Service. Our registered office is at 21 de Setiembre 3038 / 802, CP 11300, Montevideo, Uruguay. You can reach us at hi@oventab.com.
Most of what Oventab handles is business data — invoices, ingredients, recipes, margins — rather than personal data. This policy covers both, and is explicit about the two points where personal data really is at stake: the accounts of the people who use the Service, and the third-party credentials you entrust to us so we can fetch your invoices.
1. Information we collect
1.1 Information you provide
- Account sign-up: name of the business, tax ID (RUT) if you choose to enter it, your name, email address, and password. If you sign up with Google, we receive your name, email address, and profile picture from Google instead of a password.
- Account and preferences: the users you invite and their role, interface language, theme and colour palette, dashboard layout, and any notes or configuration you enter.
- Business data: the purchase invoices you load or that we retrieve for you, suppliers, ingredients, package sizes, yields, recipes, menu items, prices, and margins. Invoices may incidentally contain the name and tax ID of your suppliers, and occasionally the name of a contact person.
- Support and assistant: the messages you send us, and the conversation history with the in-app assistant, which is stored so you can pick up the thread later.
1.2 Information from Google
There are two separate, independent Google connections, and each asks only for what it needs:
-
Sign in with Google — non-sensitive identity scopes
(
openid,email,profile). We receive your name, email address, and profile picture, and use them only to create your account and sign you in. This grants no access to any other Google service. -
Google Drive —
drive.readonlyplususerinfo.email, requested only if you choose Drive as your invoice source. We use it to list and download the invoice files (XML and PDF) in the folder you designate, and we show the connected account's email address so you know which account is linked. We do not create, modify, or delete anything in your Drive.
Google API Limited Use disclosure. Oventab's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it to serve advertising, we do not allow humans to read it (except as expressly permitted by the policy — for instance with your consent for support, or where required by law), and we do not use it — and do not allow our processors to use it — to develop, improve, or train generalized or non-personalized AI/ML models.
You can revoke our access at any time from your Google Account permissions page, or by disconnecting the source from Settings. If you do, we delete the stored OAuth tokens immediately and the Drive-derived data we hold within 30 days, except for the invoices already processed into your own catalogue — which are your business records, and stay until you delete them or close your account.
1.3 Electronic-invoicing portal credentials
If you choose an e-invoicing provider as your invoice source, you give us the username and password of that portal. These are stored encrypted at rest (AES-256-GCM, with a key derived from a server-side secret), are never returned to the browser in plain text, and are used for one purpose only: signing in to that portal to download the purchase vouchers (CFE) issued to you. You can remove them at any time from Settings.
1.4 Payment information
Subscriptions are sold through our merchant of record, Paddle.com Market Limited. Paddle collects and processes the payment information you provide to complete your purchase (such as card details or billing address). Liftoff does not see or store your full payment card details. We receive from Paddle only the subscription's status, plan, dates, and identifiers. Paddle's handling of that data is governed by its Privacy Policy.
1.5 Usage and technical information
- Session and security: we record sign-in attempts (including the IP address) and rate-limiting events to detect brute force and abuse, and we keep an activity log of changes made to recipes, ingredients, and menu items so your team can see who changed what.
- Server logs: like most online services, we keep short-lived request logs (IP address, timestamp, requested path, user-agent) for security, abuse prevention, and debugging.
- No advertising or third-party analytics. The Service does not use advertising cookies, third-party analytics scripts, or cross-site trackers, and does not build advertising profiles of you.
2. How we use information
- To provide the Service: retrieve and read your invoices, keep ingredient prices current, compute recipe and menu costs, produce suggested prices, surface savings opportunities among your own suppliers, and answer your questions through the assistant;
- To manage your account and users, and to process subscriptions through Paddle;
- To send you transactional emails (account notifications, password resets, alerts you enabled) via our email provider, Resend;
- To provide support and to reproduce and fix problems you report;
- To monitor, secure, and improve the Service, including detecting fraud and abuse;
- To comply with legal obligations.
3. AI processing
The Service uses AI in exactly two places, and it is worth being precise about both:
- Invoice extraction. Invoices that arrive as XML (CFE) are parsed by our own code and never leave our servers for this purpose. Invoices that only exist as a PDF or an image are sent to our AI provider to extract the supplier, dates, line items, and amounts, which you then confirm on a review screen.
- In-app assistant. When you ask the assistant something, your question, the recent conversation, and the results of read-only queries against your own data are sent to the AI provider to compose the answer. The assistant can read your data; it can never modify it.
Our AI provider is OpenAI, used through its API under terms by which submitted data is not used to train its models. We do not send it your credentials, your password, or your payment details.
4. Legal bases (for users in the EEA, UK, and similar jurisdictions)
- Performance of a contract: to deliver the Service you signed up for;
- Consent: for the Google and e-invoicing portal connections, and for optional communications. You may withdraw consent at any time;
- Legitimate interests: to keep the Service secure, prevent abuse, and improve our product;
- Legal obligation: to comply with applicable laws.
5. How we share information
We share personal data only with service providers that help us run the Service, under written contracts that restrict their use of the data:
- OpenAI, L.L.C. — AI extraction of PDF/image invoices and the in-app assistant, as described in section 3;
- Paddle.com Market Limited — payment processing and merchant-of-record billing;
- Resend, Inc. — transactional email delivery;
- Google LLC — sign-in and, if you connect it, read access to the Drive folder you designate;
- Cloudflare, Inc. — DNS for our domains;
- Hetzner Online GmbH — the server infrastructure on which the Service and its database run;
- Slack Technologies — when a new business signs up, our internal team channel receives a notice with the business name and the email address of the person who signed up, so we can welcome and support them. No invoice or cost data is ever sent there.
We do not sell personal data, we do not share it with advertisers, and we do not share your business data with other Merchants. Every query in the Service is scoped to your business. The supplier comparison feature compares your own purchases across your own suppliers; your prices, margins, and suppliers are never shown to anyone else. We may disclose information if required by law, to protect our rights or those of our users, or in the context of a corporate transaction (merger, acquisition, restructuring), in which case we will give you notice as required by law.
6. Support access to your account
To reproduce a problem you report, a member of our platform team may open a support session that shows them the Service exactly as your account sees it. These sessions are recorded as such in our systems, are strictly limited to reading and diagnosing, and can never be used to change your subscription or billing. We use this only for support and troubleshooting.
7. International transfers
Liftoff is based in Uruguay; our service providers may process data in the United States, the European Union, the United Kingdom, and other regions. Where we transfer personal data outside your jurisdiction, we rely on appropriate safeguards (such as standard contractual clauses) where required. Uruguay has been recognized by the European Commission as providing an adequate level of data protection.
8. Data retention
- Account and business data: while your account is active and for up to twelve (12) months after cancellation, after which it is deleted or anonymized, except where we must retain it longer to comply with legal or tax obligations. You can request earlier deletion at any time;
- OAuth tokens and portal credentials: deleted as soon as you disconnect the source;
- Data derived from a connected source: deleted within 30 days of disconnection, except for invoices already processed into your own catalogue, which are your records and follow the account retention above;
- Sessions and password-reset links: sessions expire on their own; reset links are single-use and expire within one hour;
- Security logs: sign-in attempts and rate-limit events are kept for a short period for security purposes;
- Billing records: retained by Paddle and by us for the period required by applicable tax law (typically up to 10 years).
9. Your rights
Subject to applicable law, you have the right to:
- Access the personal data we hold about you;
- Correct inaccurate or incomplete data;
- Delete your data ("right to be forgotten");
- Restrict or object to certain processing;
- Receive your data in a portable format;
- Withdraw consent at any time, without affecting the lawfulness of processing carried out before withdrawal;
- Lodge a complaint with your local data-protection authority. In Uruguay, the supervisory authority under Law No. 18.331 is the Unidad Reguladora y de Control de Datos Personales (URCDP).
To exercise any of these rights, write to hi@oventab.com. We will respond within the timeframes required by applicable law.
10. Security
We use industry-standard technical and organizational measures to protect personal data:
encryption in transit (HTTPS), passwords stored only as a salted scrypt hash
(never in plain text or recoverable form), session tokens and password-reset links stored
only as a hash so a database dump opens no account, third-party credentials encrypted at
rest with AES-256-GCM, and query-level isolation so one business's data cannot be reached
from another's account. No method of transmission or storage is 100% secure; we cannot
guarantee absolute security. If a breach affects your personal data, we will notify you and
the competent authority as required by law.
11. Children
The Service is a professional tool, is not directed to children under 18, and we do not knowingly collect personal data from anyone under that age. If you believe a minor has provided us personal data, contact us so we can delete it.
12. Cookies
We use only strictly necessary cookies. There are no advertising cookies and no third-party analytics cookies. Specifically:
cp_session— keeps you signed in;cp_lang— remembers your interface language;cp_theme— remembers light or dark mode on this device;- short-lived cookies used only during a Google sign-in or Drive connection, to carry the security state of that flow and return you to the right page afterwards.
Where we ever introduce non-essential cookies, we will request your consent first.
13. Changes to this policy
We may update this Privacy Policy from time to time. If we make a material change, we will give you reasonable advance notice (for example, by email or by posting a prominent notice in the Service). The "Last updated" date at the top reflects the latest revision.
14. Contact
Questions about this Privacy Policy? Write to hi@oventab.com or to Liftoff S.R.L., 21 de Setiembre 3038 / 802, CP 11300, Montevideo, Uruguay.